New · Self-serve audits are live — real Claude Code & Cursor runs against your MCP server, SDK, or CLI →
B79/100

Static pre-check · Fri, 07 Aug 2026 06:50:55 GMT

cloudflare.com

AI agents can discover and access Cloudflare's services but lack proper authentication configuration and error documentation for reliable integration.

26 pass · 4 warn · 3 fail · 9 n/a
Discovery
21.1/22.2
Accessibility
32.1/33.3
Usability
25.6/44.4
Payments
n/a

Discovery 21.1/22.2

  • API reference linked from the homepagedetailsWARN

    no link to an API reference in the homepage HTML

    Fix: If you have an API, link its reference from the homepage. If you don't, this check is safe to ignore.

  • Canonical URL declareddetailsPASS

    https://www.cloudflare.com/

  • Documentation linked from the homepagedetailsPASS

    2 docs link(s), e.g. https://developers.cloudflare.com/

  • Homepage has a meta descriptiondetailsPASS

    68 characters

  • Homepage has a descriptive titledetailsPASS

    'Cloudflare: Build for the agent era' (35 chars)

  • Open Graph tags presentdetailsPASS

    og:title and og:description present

  • robots.txt allows agent crawlersdetailsPASS

    all 6 agent crawlers may fetch /

  • robots.txt existsdetailsPASS

    HTTP 200, 1097 bytes

  • robots.txt points at the sitemapdetailsPASS

    robots.txt has a Sitemap: line

  • sitemap.xml exists and parsesdetailsPASS

    893 URL(s) listed

  • Brand findable in agent searchdetailsN/A

    search-based checks are deferred — excluded from the score

  • Listed in an MCP registrydetailsN/A

    registry lookup not implemented in v1 — excluded from the score rather than guessed

Accessibility 32.1/33.3

  • Content-to-markup ratio is reasonabledetailsWARN

    ratio 0.0053 — 6969 readable chars in 1304340 bytes of HTML

    Fix: Most of what you serve is markup and inline script rather than content. Reduce inline payloads or server-render more text so the signal-to-noise ratio favours readers.

  • Docs are readable without JavaScriptdetailsPASS

    9318 characters of text at /docs

  • Homepage responds to an agent requestdetailsPASS

    HTTP 200 for / (agent UA)

  • Served over HTTPSdetailsPASS

    https://www.cloudflare.com/

  • Structured data (JSON-LD) on the homepagedetailsPASS

    3 valid block(s) (Organization, WebSite, WebPage)

  • llms-full.txt is publisheddetailsPASS

    HTTP 200, 155834 bytes

  • llms.txt is publisheddetailsPASS

    HTTP 200, 16880 bytes

  • Links in llms.txt resolvedetailsPASS

    5 sampled link(s) all resolve

  • llms.txt is structured markdowndetailsPASS

    has headings and markdown links

  • Serves markdown when asked for itdetailsPASS

    Accept: text/markdown → text/markdown; charset=utf-8

  • Same response for agents and browsersdetailsPASS

    both User-Agents got HTTP 200

  • Homepage has readable text without JavaScriptdetailsPASS

    6969 characters of text in the served HTML

  • No long redirect chain on the homepagedetailsPASS

    1 redirect(s)

Usability 25.6/44.4

  • MCP server completes the initialize handshakedetailsFAIL

    handshake failed: HTTP 404

    Fix: Make https://www.cloudflare.com/mcp answer a streamable-HTTP `initialize` request. Check that POST is allowed, that `Accept: application/json, text/event-stream` is honoured, and that the response is a JSON-RPC envelope.

  • OpenAPI declares its auth schemedetailsFAIL

    no securitySchemes declared

    Fix: Declare your auth in `components.securitySchemes` and reference it from operations. Without it an agent cannot tell whether a 401 means "log in" or "you are not allowed".

  • OpenAPI documents error responsesdetailsFAIL

    no 4xx/5xx responses documented on any operation

    Fix: Document your error responses with codes and schemas. Undocumented failures are where agent integrations silently break.

  • agents.md is publisheddetailsWARN

    /agents.md not served (HTTP 404)

    Fix: Publish /agents.md: what an agent may do here, which endpoints matter, auth requirements, and rate limits. It is the agent-facing counterpart to a README.

  • Errors are machine-readabledetailsWARN

    404 returns HTML, not a machine-readable body

    Fix: Content-negotiate your errors: return a JSON body with a stable `code` (and a `next_action` where recovery exists) to clients that ask for JSON.

  • A documentation endpoint respondsdetailsPASS

    /docs → HTTP 200

  • OpenAPI operations are describeddetailsPASS

    3/3 operations described (100%)

  • OpenAPI document publisheddetailsPASS

    HTTP 200, 1218 bytes of JSON

  • OpenAPI document is structurally validdetailsPASS

    OpenAPI 3.1.0, 3 path(s)

  • .well-known/mcp.json advertises an MCP serverdetailsPASS

    HTTP 200, valid JSON

  • The /api root behaves predictablydetailsN/A

    /api → HTTP 404 (no API at the conventional root)

  • MCP tool parameters are typed and describeddetailsN/A

    no listed MCP tools to inspect

  • Every MCP tool has a descriptiondetailsN/A

    no listed MCP tools to inspect

  • MCP server lists toolsdetailsN/A

    handshake did not complete, so tools/list was not reached

Payments not applicable — excluded from the score

  • Serves a 402 payment challengedetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

  • Declares AP2 / ACP supportdetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

  • Publishes x402 payment metadatadetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

Badge

Shows the current scan score and grade for this domain, straight from the latest static pre-check.

agent readiness badge for cloudflare.com
[![agent ready](/api/badge/cloudflare.com)](/score/cloudflare.com)
<a href="/score/cloudflare.com"><img src="/api/badge/cloudflare.com" alt="agent readiness score" /></a>