netlify.com

Journey

· Snapshot & citation

84/ 100

B · Ready with gaps

Waymark scored netlify.com 84/100 (B) on 24 Aug 2026.

netlify.com is usable with gaps. Payments is the strongest layer, and Discovery is the open one. Next: idempotency signal.

FindMixed
14.8/20
11 of 18 checks passed
DoorMixed
25.5/30
20 of 27 checks passed
ToolsMixed
33.8/40
10 of 13 checks passed
PayStrong
10/10
1 of 1 checks passed

What should the prompt cover?

17 findings · 15 selected

Failures (12)

Warnings (5)

Group by
1. Can an agent discover and trust you?ROBOTSSITEMAPDISCOVERYSKILLS 67/100

Whether an agent can find this origin from public files and treat it as the real one.

pass
HTTPS reachable 2/2
Evidence. Homepage responded 200 over HTTPS.
Probed homepage.
pass
robots.txt present 2/2
Evidence. Valid robots.txt with User-agent rules.
Probed robots.txt.
partial
XML sitemap 1/2
Evidence. Sitemap referenced in robots.txt only.
Probed robots.txt + sitemap.
Recommended fix. Add /sitemap.xml and reference it from robots.txt.
failed
Well-known AI catalog 0/1
Evidence. No ai-plugin.json or ai-catalog.json.
Recommended fix. Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.
failed
AGENTS.md 0/1
Evidence. agents.md status 404.
Probed public URLs named in the evidence.
Recommended fix. Publish /agents.md with agent-oriented usage notes.
pass
robots.txt AI policy Required 2/2
Evidence. Named AI crawlers: GPTBot, ChatGPT-User, Claude-Web, ClaudeBot, Google-Extended, PerplexityBot.
partial
Sitemap for agents Recommended 1/2
Evidence. Sitemap only referenced.
Recommended fix. Publish /sitemap.xml.
pass
HTTP Link header bonus 1/1
Evidence. Link: </.well-known/api-catalog>; rel="api-catalog"; type="application/linkset+json"
Probed well-known paths.
failed
ai-plugin.json bonus 0/1
Evidence. No /.well-known/ai-plugin.json.
Probed well-known paths.
Recommended fix. Optionally publish a plugin-style capability manifest.
pass
API catalog linkset bonus 2/2
Evidence. api-catalog found.
scanner error
Wikipedia sitelink bonus 0/4
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Wikidata official website bonus 0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Brand official-website match Recommended 0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
pass
Public MCP registry listing bonus 1/1
Evidence. Registry hit at https://registry.modelcontextprotocol.io/v0/servers?search=netlify.
Probed public URLs named in the evidence.
failed
Package homepage match bonus 0/1
Evidence. No npm package homepage matching netlify.com.
Probed homepage.
Recommended fix. Publish an official package whose homepage is this domain.
n/a
Sitemap lastmod bonus 0/1
Evidence. No sitemap.
n/a
related-website-set bonus 0/1
Evidence. No related-website-set (N/A unless multi-origin).
n/a
ads.txt bonus 0/1
Evidence. No ads inventory (N/A).
2. Do you welcome agents?ROBOTSCRAWLBOT AUTH 63/100

Whether crawlers and signed bots are allowed through rather than blocked at the door.

pass
AI crawlers not blanket-blocked 2/2
Evidence. No blanket Disallow: / for common AI bots.
n/a
robots Crawl-delay bonus 0/1
Evidence. No Crawl-delay (optional).
n/a
Web Bot Auth keys Recommended 0/2
Evidence. No http-message-signatures-directory.
partial
CORS / API hint 0.5/1
Evidence. No CORS header or obvious API path.
Recommended fix. If you expose an API, send Access-Control-Allow-Origin for intended clients.
failed
CSP or X-Frame-Options 0/1
Evidence. Neither CSP nor X-Frame-Options on homepage.
Probed homepage.
Recommended fix. Send Content-Security-Policy or X-Frame-Options.
3. Does an agent understand who you are and what you do?HTMLJSON-LDLLMS.TXTSKILLSDOCSNLWEB 93/100

Whether the site explains the product in language a model can ingest.

pass
Title and description 2/2
Evidence. Title and meta description present.
pass
JSON-LD structured data 4/4
Evidence. application/ld+json script found.
pass
html lang attribute 1/1
Evidence. html[lang] is set.
pass
JSON-LD entities Recommended 4/4
Evidence. Recognized schema.org types in JSON-LD.
pass
JSON-LD sameAs bonus 2/2
Evidence. sameAs present.
pass
Open Graph basics bonus 2/2
Evidence. Open Graph plus canonical.
pass
llms.txt 2/2
Evidence. Found /llms.txt with content.
pass
llms.txt index Recommended 2/2
Evidence. llms.txt has content.
pass
llms.txt size and links Recommended 2/2
Evidence. llms.txt 2815 chars, 27 URL(s).
failed
llms-full.txt bonus 0/1
Evidence. llms-full.txt status 404.
Probed public URLs named in the evidence.
Recommended fix. Optionally publish /llms-full.txt for one-shot ingest.
pass
Section llms.txt bonus 1/1
Evidence. Fetched /docs/llms.txt.
Probed public URLs named in the evidence.
n/a
NLWeb schemamap bonus 0/1
Evidence. No schemamap (N/A unless you offer NL search).
pass
Trust pages Recommended 2/2
Evidence. Trust links found.
pass
Speakable markup bonus 1/1
Evidence. Speakable markup found.
n/a
humans.txt bonus 0/1
Evidence. No /humans.txt (optional).
failed
security.txt Recommended 0/1
Evidence. No /.well-known/security.txt Contact.
Probed well-known paths.
Recommended fix. Publish /.well-known/security.txt with a Contact field.
pass
RSS or Atom feed 1/1
Evidence. Feed link detected.
pass
RSS or Atom document bonus 1/1
Evidence. Fetched a feed document.
Probed public URLs named in the evidence.
4. Can an agent integrate with you?LINKSSKILLSDOCSAPIOPSMCPSDK 87/100

Whether there is a documented machine door into the product.

failed
OpenAPI / Swagger link 0/2
Evidence. No OpenAPI/Swagger link in HTML.
Probed OpenAPI.
Recommended fix. Link to an OpenAPI or Swagger document from the homepage.
pass
Login or docs link 3/3
Evidence. Login or developer docs link found.
pass
MCP well-known card 2/2
Evidence. MCP server card found under .well-known.
Probed well-known paths.
failed
MCP SSE / HTTP hint 0/1
Evidence. No MCP/SSE hint on the homepage.
Probed homepage.
Recommended fix. Document an MCP HTTP or SSE endpoint.
n/a
openapi.json fetchable 0/0
Evidence. Fetched OpenAPI or Swagger document.
Probed OpenAPI.
pass
Webhook or API docs 2/2
Evidence. Webhook or API docs mention found.
pass
Agent skills index 2/2
Evidence. Skills index or mention found.
pass
OpenAPI document Required 5/7
Evidence. OpenAPI probe.
Probed OpenAPI.
pass
Public API surface Recommended 7/7
Evidence. Docs or API paths look callable.
pass
Developer portal Recommended 6/6
Evidence. Developer hub found.
pass
MCP server Recommended 5/6
Evidence. MCP probe.
pass
MCP server card Recommended 2/2
Evidence. MCP card JSON found.
pass
Agent Skills files bonus 2/2
Evidence. Skills file or index found.
pass
CLI tool Recommended 3/3
Evidence. CLI mention found.
n/a
GraphQL GET hint bonus 0/2
Evidence. No GraphQL surface (N/A).
n/a
OpenAPI UI page bonus 0/1
Evidence. No swagger-ui/redoc page.
n/a
OpenAPI (legacy slot) 0/0
Evidence. OpenAPI/Swagger fetched.
Probed OpenAPI.
5. Is your integration well-built?APIMCP 100/100

Whether the integration surface is complete enough to call with confidence.

n/a
MCP initialize Required 0/3
Evidence. OAuth-gated MCP at https://netlify-mcp.netlify.app/mcp (HTTP 401) — not scored.
Probed public URLs named in the evidence.
pass
MCP server card Recommended 2/2
Evidence. MCP card JSON found.
6. Can an agent use you reliably in production?MCPAPIOPS 82/100

Whether errors, idempotency, and limits are visible before a call fails.

pass
Rate limit signal Recommended 2/2
Evidence. Rate-limit or retry signal found.
partial
Idempotency signal Recommended 1/3
Evidence. API surface without idempotency notes.
Recommended fix. Document idempotency keys for mutating calls.
pass
Machine-readable errors Recommended 4/4
Evidence. JSON/problem error shape found.
pass
Honest 404 Recommended 2/2
Evidence. 404/410 on probe path.
7. Can an agent authenticate to you?SDKOAUTHAUTH.MDMCP 63/100

Whether an agent can obtain access without a human in the loop.

failed
OAuth / OIDC well-known 0/2
Evidence. No oauth-authorization-server or openid-configuration.
Recommended fix. Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.
n/a
OAuth 2.0 surface Required 0/5
Evidence. No delegated-access surface (N/A).
n/a
OAuth AS metadata Required 0/3
Evidence. No AS metadata (N/A unless you run an AS).
n/a
PKCE S256 Required 0/2
Evidence. No OAuth metadata to evaluate PKCE.
n/a
OAuth protected resource Recommended 0/2
Evidence. No OAuth resource metadata (N/A).
pass
Scoped permissions Recommended 5/5
Evidence. Named scopes found.
n/a
auth.md bonus 0/2
Evidence. No /auth.md (optional).
failed
change-password well-known bonus 0/1
Evidence. Login surface without /.well-known/change-password.
Probed well-known paths.
Recommended fix. If users have passwords, serve /.well-known/change-password.
8. Can an agent transact with you?PRICINGX402MPPUCPACPAP2 100/100

Whether an agent can price, pay, or check out on a documented rail.

pass
x402 payment bonus 2/2
Evidence. x402 or 402 payment signal.
n/a
Agentic checkout (ACP) bonus 0/3
Evidence. No ACP (N/A unless agent checkout).
n/a
ACP delegated payment bonus 0/3
Evidence. No delegated payment (N/A).
n/a
Universal Commerce Protocol bonus 0/3
Evidence. No /.well-known/ucp (N/A).
Probed well-known paths.
n/a
Machine Payments Protocol bonus 0/2
Evidence. No MPP (N/A).
pass
Pricing page Recommended 3/3
Evidence. Fetched /pricing.
Probed public URLs named in the evidence.
pass
pricing.md bonus 2/2
Evidence. Fetched /pricing.md.
Probed public URLs named in the evidence.
9. Can a user act through an agent?APPS 25/100

Whether a person can finish a job through an agent-facing UI.

failed
MCP Apps UI hint bonus 0/1
Evidence. No MCP Apps hint (N/A unless you return UI).
Recommended fix. If you return UI, declare io.modelcontextprotocol/ui resources.
n/a
A2A agent card Required 0/2
Evidence. No agent-card.json (N/A unless A2A).
partial
Web app manifest bonus 0.5/1
Evidence. manifest link without a fetchable file.
Recommended fix. Host /manifest.webmanifest if the site is installable.
10. Can an agent operate your website directly?MARKDOWNA11YHTMLWEBMCPNLWEBLLMS.TXT 100/100

Whether an agent can read and operate the site itself when there is no API or MCP.

pass
Markdown negotiation bonus 1/1
Evidence. Accept markdown returned text/markdown; charset=utf-8.
pass
/index.md fallback bonus 1/1
Evidence. Fetched /index.md.
Probed public URLs named in the evidence.
n/a
WebMCP page tools bonus 0/1
Evidence. No in-page WebMCP (N/A).
n/a
NLWeb /ask bonus 0/1
Evidence. No NLWeb /ask (N/A).
pass
Agent mode view bonus 1/1
Evidence. mode=agent responded.
Probed public URLs named in the evidence.
n/a
NodeInfo bonus 0/1
Evidence. No nodeinfo (N/A).
n/a
oEmbed discovery bonus 0/1
Evidence. No oEmbed (N/A unless embeddable).

About this snapshot & how to cite it

Public technical signals observed by Waymark. A score describes this snapshot; it does not guarantee that an agent will complete a task. Private and authenticated workflows are outside this scan.

Snapshot: . Cite the domain, score, scan time, and report URL. This URL serves the latest completed snapshot and can change after a rescan.

Methodology and limits · Markdown · JSON evidence

Scanner issues (not site fails): , , .

Share this snapshot

Embed the latest score. A badge is a public snapshot, not a certification.

Waymark score badge for netlify.com
Open badge SVG ↗

Also on the Board

Same-category snapshots, ordered by score. Scan times may differ.

Email me if this score changes

Join the monitoring waitlist. Monitoring is not active yet. This saves your interest; it does not schedule scans or send change alerts.

By joining, you agree to save your email and this domain for monitoring launch contact, for up to 180 days. Request removal via Contact. No billing.

Email this report

Send the current snapshot and a link. One email. Not a list.

We'll send netlify.com as it stands on this page.