---
title: "Waymark report for zapier.com"
canonical: "https://waymark.genedai.me/score/zapier.com"
last-updated: "2026-08-24T02:21:54.994Z"
---

# Waymark report for zapier.com

Waymark scored zapier.com 81.1/100 (B) on 24 Aug 2026.
Score: 81.1/100 — Usable with gaps
Scanned: 2026-08-24T02:21:54.994Z
Canonical report: https://waymark.genedai.me/score/zapier.com

## Layer breakdown

- Discovery: 17.8/20 (15 of 18 eligible checks passed)
- Access: 22.6/30 (17 of 25 eligible checks passed)
- Usability: 32.6/40 (12 of 16 eligible checks passed)
- Payments: N/A (excluded from the denominator)

## Findings

### 1. AGENTS.md

- Layer: discovery
- Result: failed
- Evidence: agents.md status 404.
- Recommended fix: Publish /agents.md with agent-oriented usage notes.

### 2. OpenAPI / Swagger link

- Layer: access
- Result: failed
- Evidence: No OpenAPI/Swagger link in HTML.
- Recommended fix: Link to an OpenAPI or Swagger document from the homepage.

### 3. CORS / API hint

- Layer: access
- Result: partial
- Evidence: No CORS header or obvious API path.
- Recommended fix: If you expose an API, send Access-Control-Allow-Origin for intended clients.

### 4. OAuth / OIDC well-known

- Layer: access
- Result: failed
- Evidence: No oauth-authorization-server or openid-configuration.
- Recommended fix: Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.

### 5. /index.md fallback

- Layer: access
- Result: failed
- Evidence: index.md status 404.
- Recommended fix: Serve a markdown homepage at /index.md.

### 6. MCP Apps UI hint

- Layer: usability
- Result: failed
- Evidence: No MCP Apps hint (N/A unless you return UI).
- Recommended fix: If you return UI, declare io.modelcontextprotocol/ui resources.

### 7. ai-plugin.json

- Layer: discovery
- Result: failed
- Evidence: No /.well-known/ai-plugin.json.
- Recommended fix: Optionally publish a plugin-style capability manifest.

### 8. security.txt

- Layer: access
- Result: failed
- Evidence: No /.well-known/security.txt Contact.
- Recommended fix: Publish /.well-known/security.txt with a Contact field.

### 9. change-password well-known

- Layer: access
- Result: failed
- Evidence: Login surface without /.well-known/change-password.
- Recommended fix: If users have passwords, serve /.well-known/change-password.

### 10. Rate limit signal

- Layer: usability
- Result: partial
- Evidence: API surface without a rate-limit signal.
- Recommended fix: Document or send rate-limit headers on APIs.

### 11. Idempotency signal

- Layer: usability
- Result: partial
- Evidence: API surface without idempotency notes.
- Recommended fix: Document idempotency keys for mutating calls.

### 12. Machine-readable errors

- Layer: usability
- Result: partial
- Evidence: API surface without a JSON error shape.
- Recommended fix: Return a JSON or problem+json error body.

### 13. OpenAPI document

- Layer: access
- Result: failed
- Evidence: OpenAPI probe.
- Recommended fix: Publish an OpenAPI document at a stable URL.

### 14. RSS or Atom document

- Layer: access
- Result: partial
- Evidence: No /feed or /rss.xml document.
- Recommended fix: Publish /rss.xml or /atom.xml.

### 15. Sitemap lastmod

- Layer: discovery
- Result: failed
- Evidence: Sitemap without lastmod.
- Recommended fix: Add lastmod dates to sitemap entries.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
