Pre-check scan
The checks
Every check the scanner runs, by layer, with its weight and generic fix.
All 42 checks, grouped by layer. This table renders from the scanner's own check manifest, so it is always exactly what runs. The fix shown here is the generic form — a real scan replaces it with one written against your site's specific failure.
Discovery — 20 points
| check | wt | generic fix |
|---|---|---|
api-linkedAPI reference linked from the homepage | 2 | If you have an API, link its reference from the homepage. If you don't, this check is safe to ignore. |
brand-findableBrand findable in agent search | 2 | — |
canonical-urlCanonical URL declared | 1 | Add <link rel="canonical"> to the homepage so agents and crawlers converge on one URL for this page. |
docs-linkedDocumentation linked from the homepage | 3 | Link your docs from the homepage with visible anchor text ("Docs", "Documentation", "Developers"). An agent that cannot find your docs from your homepage will guess your API. |
homepage-meta-descriptionHomepage has a meta description | 2 | Add a <meta name="description"> of 50–200 characters summarising what the product does. Agents use it as the one-line answer to "what is this site". |
homepage-titleHomepage has a descriptive title | 2 | Add a <title> of 10–70 characters naming the product and what it does — it is the first thing an agent reads to decide what this site is. |
mcp-registry-listedListed in an MCP registry | 2 | — |
open-graphOpen Graph tags present | 1 | Add og:title and og:description meta tags. |
robots-allows-agentsrobots.txt allows agent crawlers | 4 | — |
robots-presentrobots.txt exists | 2 | An empty robots.txt is permissive but says nothing. State your crawl rules and point at your sitemap with `Sitemap: https://…/sitemap.xml`. |
sitemap-in-robotsrobots.txt points at the sitemap | 1 | Add `Sitemap: https://<domain>/sitemap.xml` to /robots.txt so crawlers find it without guessing. |
sitemap-presentsitemap.xml exists and parses | 3 | Publish /sitemap.xml listing your public pages, and reference it from robots.txt with a `Sitemap:` line. |
Accessibility — 30 points
| check | wt | generic fix |
|---|---|---|
docs-reachableDocs are readable without JavaScript | 4 | — |
homepage-reachableHomepage responds to an agent request | 5 | — |
httpsServed over HTTPS | 2 | — |
jsonld-presentStructured data (JSON-LD) on the homepage | 2 | Add a JSON-LD block (schema.org Organization or SoftwareApplication) so agents get your name, description and links as data rather than prose. |
llms-full-txtllms-full.txt is published | 1 | Optional but cheap: publish /llms-full.txt with your docs inlined as one markdown file, so an agent can read everything in a single fetch. |
llms-txt-existsllms.txt is published | 4 | Publish /llms.txt: a plain-markdown index that tells an agent what this product is and where the authoritative docs live. It is the cheapest high-leverage file you can add. |
llms-txt-links-resolveLinks in llms.txt resolve | 3 | — |
llms-txt-parsesllms.txt is structured markdown | 2 | — |
markdown-negotiationServes markdown when asked for it | 2 | Optional but increasingly expected: honour `Accept: text/markdown` by serving a markdown rendering of the page, so agents skip HTML parsing entirely. |
no-ua-discriminationSame response for agents and browsers | 5 | — |
nojs-text-presentHomepage has readable text without JavaScript | 6 | Server-render the homepage's core content (SSR, static export, or prerendering). A client-rendered shell is empty to every agent. |
nojs-text-ratioContent-to-markup ratio is reasonable | 3 | — |
redirect-sanityNo long redirect chain on the homepage | 1 | — |
Usability — 40 points
| check | wt | generic fix |
|---|---|---|
agents-mdagents.md is published | 3 | Publish /agents.md: what an agent may do here, which endpoints matter, auth requirements, and rate limits. It is the agent-facing counterpart to a README. |
api-endpoint-behaviourThe /api root behaves predictably | 2 | — |
docs-endpointA documentation endpoint responds | 3 | Serve docs at the conventional /docs path, or redirect it to wherever they live. Agents try conventional paths first. |
error-envelopeErrors are machine-readable | 4 | Content-negotiate your errors: return a JSON body with a stable `code` (and a `next_action` where recovery exists) to clients that ask for JSON. |
mcp-handshakeMCP server completes the initialize handshake | 5 | — |
mcp-param-schemasMCP tool parameters are typed and described | 4 | — |
mcp-tool-descriptionsEvery MCP tool has a description | 3 | — |
mcp-tools-listedMCP server lists tools | 4 | — |
openapi-auth-schemeOpenAPI declares its auth scheme | 4 | — |
openapi-descriptionsOpenAPI operations are described | 3 | — |
openapi-existsOpenAPI document published | 5 | If you have an HTTP API, publish its OpenAPI document at a predictable path (/openapi.json). It is the difference between an agent reading your contract and an agent guessing it. If you have no HTTP API, ignore this. |
openapi-typed-errorsOpenAPI documents error responses | 4 | — |
openapi-validOpenAPI document is structurally valid | 4 | — |
wellknown-mcp.well-known/mcp.json advertises an MCP server | 4 | If you run an MCP server, advertise it at /.well-known/mcp.json so agents discover it without being told its URL. |
Payments — 10 points
| check | wt | generic fix |
|---|---|---|
payments-402-challengeServes a 402 payment challenge | 4 | — |
payments-ap2-acpDeclares AP2 / ACP support | 3 | — |
payments-x402-metadataPublishes x402 payment metadata | 3 | — |