170 domains · formula v9.2
The market solved being read by agents. It has not solved being joined by one.
Every domain Let Agents In has scanned, aggregated. Documentation is reachable, parseable and mostly open to AI crawlers. Then the funnel stops: almost nothing on this list can take an agent from reading about the product to holding a working credential.
91%
of the measurable points for being found and read, on average
26%
of the measurable points for having a door an agent can walk through
Where the funnel collapses
Mean share of the points we could actually measure at each stage. Checks we could not evaluate are excluded from the denominator rather than counted as failures, and the count of domains behind each row is printed with it, because our coverage is not equal across stages.
- 134 of 170 answer none of the nine known agent entry paths: no /agent-signup.md, no /.well-known/agent-access.json, nothing. A further 7 publish a service descriptor but no procedure written for a machine.
- 77 of 154 describe no way to obtain a credential without a human opening a dashboard, across every documentation page we could read. The remaining 16 gave us too little documentation to judge.
- 102 of 170 publish no OAuth metadata with a registration endpoint on any host we could follow, so an agent cannot register itself as a client. RFC 7591 is the only standard by which it could. The other side of that number is worth as much: where a vendor does publish one, it almost always sits on the MCP host and arrived with the server, because the specification asks for it.
- 29 of 170 run an MCP server and document no way for an agent to obtain a credential for it. That pair is the whole finding: a door built for a machine, and nothing behind it the machine can unlock on its own.
- 68 of 170 run an MCP server that answers a handshake. That is the one part of this funnel the market has moved on, and it stops there: a server an agent can call is not a credential an agent can get, and the two stages below this one say so.
Every check, across the corpus
Unmeasurable is its own column on purpose. A check we could not evaluate is our blind spot, and folding it into failures would make the market look worse than we can prove it is.
Scroll the table sideways for the last column.
| Check | Pass | Partial | Zero | Unmeasurable |
|---|---|---|---|---|
| Answers an agent user-agent | 164 | 0 | 4 | 2 |
| llms.txt published | 123 | 0 | 47 | 0 |
| Docs readable without JavaScript | 147 | 0 | 11 | 12 |
| On-demand agents not blocked | 160 | 0 | 5 | 5 |
| Paths robots.txt points at answer | 11 | 0 | 3 | 156 |
| No punishing crawl delay | 163 | 0 | 2 | 5 |
| Agent entry point | 11 | 7 | 134 | 18 |
| OAuth dynamic client registration | 68 | 0 | 102 | 0 |
| MCP surface | 68 | 0 | 98 | 4 |
| No CAPTCHA in the signup HTML | 20 | 0 | 29 | 121 |
| Signup reachable without a browser | 40 | 0 | 88 | 42 |
| Programmatic key provisioning | 28 | 49 | 77 | 16 |
| Free tier or no-card trial stated in text | 118 | 0 | 19 | 33 |
| Typed SDK on the registry | 147 | 0 | 9 | 14 |
| Machine-readable API description | 110 | 0 | 57 | 3 |
Both ends of the corpus
Highest
- openrouter.ai14/15
- zenrows.com13/14
- cloudflare.com13/14
- firecrawl.dev14/16
- browserbase.com14/16
Lowest
- june.so3/15
- hover.com3/11
- lemonsqueezy.com5/15
- prosemirror.net4/11
- godaddy.com3/8
Scores are out of the points we could measure on each domain, not out of 17. A site that refuses our requests scores against a smaller denominator, not a worse number. Every one of these links is the full scorecard, with the HTTP observation behind each line.
What this is not
- Not a random sample. These are developer tools we chose, in categories where an agent picking a building block is a real purchase decision. A scan anyone runs on this site gets its own permanent link and is compared against this corpus, but never joins it.
- Not thick enough for category rankings to be read as league tables. Most categories hold five or six vendors, so one of them moving is worth several points of the category share, which is more than the 0.20 percent the whole corpus moves between two identical rescans. Compare a vendor with its own past scans and with the named peers on its scorecard, not with a category average built on six rows.
- Not equally measurable across stages. Coverage differs check by check, the n on each stage row is the number of domains behind it, and the table above prints what we could not evaluate rather than burying it in the failures.
- Not a measure of whether agents actually choose these products. That takes running agents against real tasks, which is a different instrument and a paid one.
- Not stable across formula versions. Everything here is scored under v9.2; earlier numbers were produced by a formula with known defects, and mixing them would be dishonest.
- Scanned between 2026-08-12 and 2026-08-12. Sites change, and so does this page: it recomputes from the store on every request rather than quoting a frozen number.
Take the data
Every row behind this page, one entry per domain and check, with the verdict, the points and the sentence we measured it from. Free to use and quote with attribution. Disagreeing with us is easier with the data than with the prose.
/corpus.json/corpus.csvHow every check is defined and scored