---
title: "Waymark report for aisa.one"
canonical: "https://waymark.genedai.me/score/aisa.one"
last-updated: "2026-09-13T12:17:19.278Z"
---

# Waymark report for aisa.one

Waymark scored aisa.one 84/100 (B) on 13 Sep 2026.
Score: 84/100 — Usable with gaps
Scanned: 2026-09-13T12:17:19.278Z
Canonical report: https://waymark.genedai.me/score/aisa.one

## Layer breakdown

- Discovery: 16.4/20 (15 of 20 eligible checks passed)
- Access: 25.4/30 (25 of 34 eligible checks passed)
- Usability: 32.1/40 (19 of 25 eligible checks passed)
- Payments: 10/10 (2 of 2 eligible checks passed)

## Findings

### 1. AGENTS.md

- Layer: discovery
- Result: failed
- Evidence: agents.md status 404.
- Recommended fix: Publish /agents.md with agent-oriented usage notes.

### 2. OpenAPI / Swagger link

- Layer: access
- Result: failed
- Evidence: No OpenAPI/Swagger link in HTML.
- Recommended fix: Link to an OpenAPI or Swagger document from the homepage.

### 3. RSS or Atom feed

- Layer: access
- Result: failed
- Evidence: No RSS/Atom link.
- Recommended fix: Expose an RSS or Atom feed for machine subscribers.

### 4. CSP or X-Frame-Options

- Layer: access
- Result: failed
- Evidence: Neither CSP nor X-Frame-Options on homepage.
- Recommended fix: Send Content-Security-Policy or X-Frame-Options.

### 5. OAuth / OIDC well-known

- Layer: access
- Result: failed
- Evidence: No oauth-authorization-server or openid-configuration.
- Recommended fix: Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.

### 6. robots.txt AI policy

- Layer: discovery
- Result: partial
- Evidence: robots.txt present but no named AI crawlers.
- Recommended fix: Name GPTBot, ClaudeBot, Google-Extended, PerplexityBot and state allow or deny.

### 7. HTTP Link header

- Layer: discovery
- Result: failed
- Evidence: No rel=sitemap|describedby|api-catalog|alternate on homepage.
- Recommended fix: Send RFC 8288 Link headers for related machine resources.

### 8. API catalog linkset

- Layer: discovery
- Result: failed
- Evidence: API present without RFC 9727 catalog.
- Recommended fix: Add /.well-known/api-catalog pointing at OpenAPI.

### 9. security.txt

- Layer: access
- Result: failed
- Evidence: No /.well-known/security.txt Contact.
- Recommended fix: Publish /.well-known/security.txt with a Contact field.

### 10. change-password well-known

- Layer: access
- Result: failed
- Evidence: Login surface without /.well-known/change-password.
- Recommended fix: If users have passwords, serve /.well-known/change-password.

### 11. Idempotency signal

- Layer: usability
- Result: partial
- Evidence: API surface without idempotency notes.
- Recommended fix: Document idempotency keys for mutating calls.

### 12. Machine-readable errors

- Layer: usability
- Result: partial
- Evidence: API surface without a JSON error shape.
- Recommended fix: Return a JSON or problem+json error body.

### 13. Organization schema completeness

- Layer: access
- Result: failed
- Evidence: Organization JSON-LD missing contactPoint and address.
- Recommended fix: Add Organization JSON-LD that includes both contactPoint (with email/phone and contactType) and address (PostalAddress).

### 14. Markdown frontmatter metadata

- Layer: access
- Result: failed
- Evidence: Served markdown has no YAML frontmatter block.
- Recommended fix: Open served markdown with a --- frontmatter block carrying title plus description, canonical, or last-updated.

### 15. Accessible document structure

- Layer: usability
- Result: partial
- Evidence: Landmarks partial (main=false nav=true h1=true skip=false).
- Recommended fix: Give the homepage a main region, nav, H1, and a heading order that does not skip levels.

### 16. Registry branding

- Layer: discovery
- Result: failed
- Evidence: MCP card missing icon.
- Recommended fix: Give your MCP server-card a display name, an icon or logo, and a description.

### 17. REST response schema coverage

- Layer: usability
- Result: partial
- Evidence: Spec truncated; response schema coverage looks partial.
- Recommended fix: Define typed JSON response schemas for endpoints in your OpenAPI spec.

### 18. Function calling compatibility

- Layer: usability
- Result: failed
- Evidence: Spec is missing unique operationIds/descriptions for function calling.
- Recommended fix: Give endpoints unique operationIds, typed schemas, and descriptions for function calling.

### 19. Multi-language SDK packages

- Layer: usability
- Result: partial
- Evidence: npm matches; second ecosystem homepage does not.
- Recommended fix: Publish official SDK packages on npm and PyPI whose homepage is this domain.

### 20. Agent-UA markdown docs

- Layer: access
- Result: failed
- Evidence: Docs host did not serve markdown to GPTBot (HTTP 522, text/plain; charset=utf-8).
- Recommended fix: Serve text/markdown to GPTBot (and similar agent UAs) on your docs host.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
