Let Agents In

Agent readiness · Authentication as a service

stytch.com

9 of 14 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with. 2 of them could not be measured from where we ask, and those are left out of the denominator rather than counted as failures.

A · Discovery

  • PASS
    Answers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
  • PASS
    llms.txt publishedllms.txt and llms-full.txt present at https://stytch.com/llms.txt and https://stytch.com/llms-full.txt and https://docs.stytch.com/llms.txt, and the 12 links we sampled across both files all answer
  • PASS
    Docs readable without JavaScript13,855 characters of text without JS, on https://stytch.com/docs/api-reference/consumer/api/passkeys-webauthn/list-webauthn-credentials rather than on https://stytch.com/docs/get-started/overview
  • PASS
    On-demand agents not blockedNo on-demand agent is blocked
  • N/A
    Paths robots.txt points at answerrobots.txt names no concrete path, only patterns or nothing, so there is no claim to check
  • PASS
    No punishing crawl delayNo Crawl-delay applies to the agents we check

B · Agent entry

  • FAIL
    Agent entry pointNone of the 9 known agent entry paths returns a file rather than your page shell
  • FAIL
    OAuth dynamic client registrationNo OAuth metadata on any of the 8 hosts probed, including the usual auth and api subdomains
  • FAIL
    MCP surfaceMCP mentioned 69x in your own files, but nothing answered at mcp.stytch.com, mcp.stytch.com/mcp, mcp.stytch.com/v1/mcp, api.stytch.com/mcp, /mcp or /api/mcp

C · Registration

  • UNMEASURED
    No CAPTCHA in the signup HTMLUnmeasurable: we found no link to an account signup on the pages we read, while you publish prices at https://stytch.com/pricing, so this is a gap in our reading rather than a finding about youLink signup from your home page or your pricing page and this becomes measurable.
  • UNMEASURED
    Signup reachable without a browserUnmeasurable: we found no link to an account signup on the pages we read, while you publish prices at https://stytch.com/pricing, so this is a gap in our reading rather than a finding about youLink signup from your home page or your pricing page and this becomes measurable.

D · Provisioning

  • PART
    Programmatic key provisioning1 of 7 provisioning phrases across the 7 documents we read: "management api"
  • PASS
    Free tier or no-card trial stated in textFree tier or no-card signals at https://stytch.com/pricing: "free tier", "$0", "Always free"

E · Integration

  • PASS
    Typed SDK on the registrystytch@14.2.0 ships types, matched from the registry by who publishes it rather than by a link on your site
  • PASS
    Machine-readable API descriptionDocs serve markdown to machines, at https://stytch.com/docs/get-started/overview

Tell me when this changes

The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.

This page is the newest scan we hold for stytch.com and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.

Scan a domain yourself