Methodology
Waymark scores observed public website evidence across four weighted layers; non-applicable and scanner-error checks are excluded, and Journey never changes the score.
Waymark estimates how readily AI agents can discover, access, use, and (when relevant) pay on a public website. The score is an at-a-glance summary; the individual checks and evidence are the useful part of the report.
What the score represents
An agent has to find you, get in, handshake a contract, and — only if you sell — pay. The number is not a brand opinion. It combines earned points divided by eligible maximum points within each layer, then applies the layer weights. Checks can earn partial credit, so this is a weighted score, not a simple pass rate. Grades: A+ at 95, A at 86, B at 70, C at 48, D at 28, otherwise F. A low grade means an agent is likely to stop and try another product.
Scoring model
The official stack is Discovery 20, Access 30, Usability 40, Payments 10. Those four weights add to 100. N/A and scanner error drop out of the denominator so a missing optional protocol does not count as a fail. Fail means the site should have shown the signal and did not. Journey is never in this number.
Discovery asks whether an agent can locate the map. We follow docs., mcp., api., and developers. hosts, and we guess those names on the apex. Maps include robots, sitemap, and llms.txt. Credit only after a fetch. Mention-only is warn.
Access asks whether a bot is allowed in: headers, robots policy, login or docs, OAuth when it applies. A guessed 401 on a random host is not a server unless the site already showed evidence.
Usability asks whether the product can handshake a contract. OpenAPI must fetch. MCP must initialize. OAuth-gated MCP still counts as MCP (pass at 5/6). Mention without handshake is warn.
Payments is N/A unless we see a cart, SKU, or checkout, or a live rail (x402, UCP, ACP, MPP). Marketing a payments company is not commerce. N/A drops out.
How a check counts
A pass can earn full or partial points under its check rule: OAuth-gated MCP is a pass at 5/6. Warn generally earns 1 point when the check maximum is at least 2; check-specific rules determine the actual points. Fail earns 0. Status na and scanner error leave the denominator. Fail is not rewritten to N/A to inflate a total.
Caps and degraded
A homepage error marks the scan degraded. Degraded totals cap at 47 and stay off the board. If scored weight is under 50, the total caps below 70. Degraded rows never mint A or B from leftover thin passes.
Journey is not the score
Journey is a walk of a stated intent. It is supporting evidence only. It does not change the official number.
Data source / what we fetch
The scanner identifies as WaymarkBot/1.0 with an 8s timeout. Homepage HTML may wait for network idle via Browser Rendering and fail open to fetch. Protocol files are raw fetch. We follow where an agent would go — docs., mcp., api., developers. — and we parse cards and catalogs before we guess hosts. A random 401 on a guessed MCP host is not treated as a server unless the site already showed MCP evidence.
Freshness
Completed reports are stored on this worker. Cache default is 6 hours unless you pass force on a new scan. The retrieve API returns the latest stored snapshot; it does not refresh the site.
Limitations
- This is not a security, accessibility, legal, or compliance certificate.
- We do not evaluate private or authenticated product states.
- A missing report is not a zero — it means no snapshot is stored yet.
- Review the evidence on the score page before you quote the grade.
Catalog
Live checks. Weights stay Discovery 20 / Access 30 / Usability 40 / Payments 10. AgentReady AR-* ids on some checks are coverage references, not imported scoring.
Discovery
- HTTPS reachable ·
https-ok - robots.txt present ·
robots-txt - XML sitemap ·
sitemap-xml - llms.txt ·
llms-txt - AGENTS.md ·
agents-md - Well-known AI catalog ·
well-known-ai-catalog - robots.txt AI policy ·
wm-robots-ai-policy - Sitemap for agents ·
wm-sitemap - llms.txt index ·
wm-llms-txt - llms-full.txt ·
wm-llms-full-txt - HTTP Link header ·
wm-http-link-header - NLWeb schemamap ·
wm-nlweb-schemamap - ai-plugin.json ·
wm-ai-plugin - API catalog linkset ·
wm-api-catalog - ads.txt ·
wm-ads-txt - llms.txt size and links ·
wm-llms-txt-quality - robots Crawl-delay ·
wm-robots-crawl-delay - related-website-set ·
wm-related-website-set - Wikipedia sitelink ·
wm-wikipedia - Wikidata official website ·
wm-wikidata - Brand official-website match ·
wm-brand-web - Public MCP registry listing ·
wm-mcp-registry - Agent mode view ·
wm-agent-mode - Section llms.txt ·
wm-docs-llms - Sitemap lastmod ·
wm-sitemap-lastmod - Package homepage match ·
wm-pkg-home
Access
- Title and description ·
title-meta - JSON-LD structured data ·
json-ld - OpenAPI / Swagger link ·
openapi-or-swagger-link - html lang attribute ·
html-lang - RSS or Atom feed ·
feed-or-rss - CSP or X-Frame-Options ·
security-headers - CORS / API hint ·
cors-on-api-hint - OAuth / OIDC well-known ·
oauth-well-known - Login or docs link ·
login-or-docs-link - AI crawlers not blanket-blocked ·
not-blocking-common-ai-bots - JSON-LD entities ·
wm-json-ld - Markdown negotiation ·
wm-markdown-negotiate - /index.md fallback ·
wm-index-md - Speakable markup ·
wm-speakable - OAuth 2.0 surface ·
wm-oauth - OAuth AS metadata ·
wm-oauth-as-metadata - PKCE S256 ·
wm-pkce - Web Bot Auth keys ·
wm-web-bot-auth - OAuth protected resource ·
wm-oauth-resource - security.txt ·
wm-security-txt - humans.txt ·
wm-humans-txt - change-password well-known ·
wm-change-password - web-app-origin-association ·
wm-web-app-origin-association - assetlinks.json ·
wm-assetlinks - apple-app-site-association ·
wm-apple-app-site-association - Web app manifest ·
wm-web-manifest - oEmbed discovery ·
wm-oembed - Developer portal ·
wm-dev-portal - Trust pages ·
wm-trust-pages - Pricing page ·
wm-pricing-page - Scoped permissions ·
wm-scopes - Public API surface ·
wm-public-api - RSS or Atom document ·
wm-feed-file - pricing.md ·
wm-pricing-md - NodeInfo ·
wm-nodeinfo - auth.md ·
wm-auth-md - JSON-LD sameAs ·
wm-sameas - Open Graph basics ·
wm-og-meta
Usability
- MCP well-known card ·
mcp-well-known - MCP SSE / HTTP hint ·
mcp-sse-or-http-hint - openapi.json fetchable ·
openapi-json-fetchable - Webhook or API docs ·
webhook-or-api-docs - Agent skills index ·
skill-or-agent-skills-index - MCP initialize ·
wm-mcp-initialize - A2A agent card ·
wm-a2a-card - OpenAPI document ·
wm-openapi - MCP server card ·
wm-mcp-card - MCP Apps UI hint ·
wm-mcp-apps - WebMCP page tools ·
wm-webmcp - NLWeb /ask ·
wm-nlweb-ask - Agent Skills files ·
wm-agent-skills - Rate limit signal ·
wm-rate-limit-hint - Idempotency signal ·
wm-idempotency-hint - Machine-readable errors ·
wm-json-error-hint - CLI tool ·
wm-cli - Honest 404 ·
wm-agent-404 - MCP server ·
wm-mcp - OpenAPI UI page ·
wm-openapi-ui - GraphQL GET hint ·
wm-gql-hint
Payments
- x402 payment ·
wm-x402 - Agentic checkout (ACP) ·
wm-acp - ACP delegated payment ·
wm-acp-delegate - Universal Commerce Protocol ·
wm-ucp - Machine Payments Protocol ·
wm-mpp
Provenance and how to cite this score
Waymark is an independent Gene / Digidai product. Its public check catalog defines the evidence used by the scanner. A report describes one public URL at its stored scan time; it is not a global study or third-party certification.
Cite: “Waymark scored [domain] [score]/100 ([grade]) on [scanned_at], [canonical report URL].” Include the timestamp and link, and retain the JSON or Markdown snapshot if the original evidence matters: the stable URL serves the latest completed report after a rescan.
Retrieve the JSON or Markdown evidence. A missing report is not a score of zero.