Agent Commerce Readiness
Can an AI agent transact with a site — not just read it, but authenticate without borrowing a human’s password, discover an API, read a price, obtain a credential of its own?
What it asks
Citation Readiness asks whether an AI assistant can reach, read and cite a site. This is a different question, run on the same scan: whether an AI agent could act on it. There is no score, on purpose. The capability matrix is the ground truth — eight cells, each a reproducible fact about what a server said to us — and the tier is a name for a bundle of those facts, decided by published predicates rather than a judgement call.
It runs only when the owner of a scan asks for it, never affects the Citation Readiness score, and no language model is consulted anywhere in it.
What we check
The same eight cells the matrix and the public index read, so this list can never describe a check differently than the one that actually ran.
- Agent access to the commerce page — The same commerce page requested as a browser and again as each AI agent, compared for whether the price or title an agent sees matches what a browser sees.
- Price legibility — Whether a price is somewhere a machine can read it without running the page. Prices are read as text because none of the nine real pricing pages we surveyed marked them up with JSON-LD; a rubric keyed on schema would score everybody zero and tell nobody anything.
Sources: JSON-LD 1.1
- Rate-limit and error shape — When an agent hits your API unauthenticated, is it told how to behave: standard rate-limit headers, a machine-readable error body, or neither.
Sources: IETF draft: RateLimit header fields for HTTP · RFC 9457: Problem Details for HTTP APIs
- robots.txt vs the edge — What your robots.txt says about agents against what your edge actually does to them, because the two are allowed to disagree and frequently do.
Sources: RFC 9309: Robots Exclusion Protocol
- Machine credentials (OAuth) — Whether an agent can obtain its own credentials, read from OAuth authorization-server and OpenID discovery documents. client_credentials must be declared explicitly, because RFC 8414 says an absent grant-types array defaults to authorization_code and implicit — so silence on this one is a negative, not an unknown.
- UCP manifest — /.well-known/ucp, the one agent-commerce protocol with a mandatory public discovery document, validated against the shape two live merchants actually serve rather than an idealised reading of the spec.
Sources: Universal Commerce Protocol
- OpenAPI document — A discoverable, parseable API description. A 200 only counts if the body is JSON with an openapi or swagger key, because a single-page app will happily serve its app shell at any path we guess.
Sources: OpenAPI Specification 3.1.0
- MCP endpoint — The spec mandates a 405 to a GET on an MCP endpoint, which is how we fingerprint one for free; only where that fires do we send the single server/discover request, a parameterless, cacheable metadata read the spec itself marks public.
Sources: Model Context Protocol specification (2026-07-28) · Model Context Protocol specification · MCP specification: transports
The tiers
The tier is the highest rung whose predicates are all proven true. An unknown cell stops the climb there and is not counted against a site — nobody reaches a tier through a cell we could not read, and it never denies one either.
| Tier | Predicate |
|---|---|
| T0 · Not agent-readable | Agents are refused the commerce pages, or no price is readable without running the page. |
| T1 · Agent-readable | An agent gets the commerce page, and the prices are text the server sent. |
| T2 · Agent-operable | An unauthenticated API request is answered with something a machine can act on (rate-limit headers, a machine-readable error, or a structured JSON answer), and what robots.txt says about agents agrees with what the edge does. |
| T3 · Agent-integratable | A real machine interface exists — a parseable OpenAPI document, a live MCP endpoint, or a valid UCP manifest. Any one. |
| T4 · Agent-transactable | An agent can obtain its own credentials — client_credentials declared explicitly, or dynamic client registration. |
| T5 · Agent-payable | The site answers with a machine-payable challenge — x402 (v1 or v2) or L402 — so an agent that holds credentials could settle without a human. We observe the challenge; we never settle it. |
| Ungraded | Not a tier: the browser baseline itself was refused, so nothing could be compared. A site we could not measure has not earned a grade; it has produced no evidence. |
Sources: x402 payment protocol · L402: Lightning HTTP 402 protocol
DIVERGENT
A site can serve an agent a real commerce page whose price or title differs from what a browser sees at the same URL — silent wrongness, because nothing signals it, and an agent quoting the page quotes a number the human next to it never saw. That site is still served, so it can still climb the ladder: DIVERGENT is raised beside the tier, with both sets of prices shown, and the reader judges. It never moves the tier itself.
What we never do
- Structured receipts: they sit behind a completed transaction, and we never transact.
- The OpenAI/Stripe Agentic Commerce Protocol and Google's AP2: both describe exchanges between parties who have already agreed to trade, and leave no server-side artefact a GET request can see.
- Anything that needs a login we have no credential for. When you give a scan a staging basic-auth username and password, it is reused for ACR requests to that scan's own origin only — never sent to any other host a probe discovers — and we still cannot reach a login only a human browser session establishes.
It never submits a form and never attempts a payment of any kind, and it sends never more than 40 read-only requests against a site, usually well under that, honouring robots.txt for every path it touches.
How to run it
Only the signed-in owner of a scan can run it, from that scan’s report page, and only by choosing to — it never runs on its own. A commerce page can be declared by hand there if it sits somewhere our scanner would not otherwise recognise (something other than a URL containing pricing, plans or price), and that declared page is used in place of a guess.
One audit is stored per scan; running it again means declaring a different commerce page, which clears the stored result, or starting a new scan of the site.
Check a predicate yourself
Request a pricing page as a browser, then again with an AI agent’s published user-agent string, and compare status, size and whether the price survived:
curl -sI -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36" https://example.com/pricing
curl -sI -A "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" https://example.com/pricingFetch the OAuth authorization-server metadata document and read what it declares. RFC 8414 says an absent grant_types_supported array defaults to authorization_code and implicit — so client_credentials has to be listed explicitly for a machine to know it can authenticate without a human’s browser session:
curl -s https://example.com/.well-known/oauth-authorization-server | jq '.grant_types_supported'Questions
What is Agent Commerce Readiness?
A second audit on the same scan. The Citation Readiness score asks whether an AI assistant can reach, read and cite a site; this asks whether an AI agent could transact with it. Eight read-only checks are bundled into a tier, T0 up to T5, by published predicates. There is no score, on purpose.
Does it change my Citation Readiness score?
No. It has its own rubric version, its own table and its own predicates, and nothing in it feeds the score. Running it moves no number anywhere.
Who can run it, and does it run on its own?
Only the signed-in owner of a scan, from the report page, and only when they ask. It never runs automatically on a site.
What does it do to my server?
Never more than 40 read-only requests, usually well under that. It honours your robots.txt for every path, sends exactly one POST (an MCP server/discover, and only after a GET has answered 405), and never submits a form or a payment.
Sources: Model Context Protocol specification (2026-07-28) · RFC 9309: Robots Exclusion Protocol · Model Context Protocol specification
What do the tiers mean?
T0 Not agent-readable, T1 Agent-readable, T2 Agent-operable, T3 Agent-integratable, T4 Agent-transactable, T5 Agent-payable — each rung a bundle of reproducible facts decided by a published predicate, checkable with curl; the full predicate for each is on the methodology page. Ungraded is not a tier: it means the browser baseline itself was refused or a first-rung cell could not be read, so nothing could be compared.
Is Ungraded a bad grade?
No. Ungraded is not a tier. It means the browser baseline itself was refused or a first-rung cell could not be read, so nothing could be compared. A site we could not measure has produced no evidence, and T0 is a claim we only make when we looked and found agents refused or prices illegible.
What does citefiles.com grade on its own rubric?
T0, Not agent-readable. Our pricing page is /pro, and it carries no price yet — it describes a product that is not for sale — so the first rung fails honestly: the page was found, read as a browser and as each agent, and no price appears in it. Our MCP endpoint answers 405 to a GET and describes itself to a server/discover request, so T3's interface predicate would be met, but the ladder is climbed rung by rung and T1 is not. Until this build the same site read Ungraded, because the scanner only recognised a pricing page by the words pricing, plans or price in its path; the changelog records the change.
Sources: Model Context Protocol specification (2026-07-28) · Model Context Protocol specification · MCP specification: transports
What is DIVERGENT?
A site can serve an agent a real commerce page whose price or title differs from what a browser sees at the same URL. That site is still served, so it can still climb the ladder; the flag is raised beside the tier with both sets of prices shown, and the reader judges. It never moves the tier.
Does it test whether an agent can actually pay?
No — we never settle a challenge. T5 means the site ANSWERS with a machine-payable challenge (x402 or L402) that a credentialed agent could settle; that is an offer we can see with one request, not a transaction. Cloudflare's pay-per-crawl and a bare 402 with no machine-readable challenge stay recorded as watch items, never graded, and completing a trade leaves nothing a GET can see.
Sources: x402 payment protocol · L402: Lightning HTTP 402 protocol
What are UCP, MCP, OpenAPI and x402, in one line each?
UCP is a public manifest at /.well-known/ucp describing a merchant's agent-commerce services. MCP is the Model Context Protocol, an endpoint that answers 405 to GET and describes itself to one server/discover request. OpenAPI is a JSON description of an HTTP API with an openapi or swagger key. x402 (v1 or v2) is an HTTP 402 carrying a machine-readable challenge in a header that a credentialed agent could settle without a human; L402 is the same idea over a Lightning macaroon. We record the challenge shape and grade it at T5; we never settle one.
Sources: Model Context Protocol specification (2026-07-28) · Universal Commerce Protocol · Model Context Protocol specification · MCP specification: transports · OpenAPI Specification 3.1.0 · x402 payment protocol · L402: Lightning HTTP 402 protocol
How do I check a predicate myself?
Every predicate is a curl. Request your pricing page with a browser user-agent and again with an agent's published user-agent string and compare status, size and title. Fetch /.well-known/oauth-authorization-server and read grant_types_supported: client_credentials must appear explicitly, because the RFC 8414 default excludes it. GET your MCP path and expect 405; anything else is not an MCP endpoint by the spec.
Sources: RFC 8414: OAuth 2.0 Authorization Server Metadata · MCP specification: transports
Why is the T2 rung about robots.txt at all?
Because robots.txt is what a site says about agents and the edge is what it does, and the two are allowed to disagree. A robots.txt that allows agents while the edge challenges them is a contradiction, and only the enforced one is what an agent meets. Coherent-closed is honest and fails T2 honestly.
Sources: RFC 9309: Robots Exclusion Protocol
How do I remove my site, or stop the check running?
Write to [email protected] from an address at that domain and we remove it without asking why. To stop the check reading your site, disallow CiteFilesBot in robots.txt; the audit honours it for every path.
Sources: RFC 9309: Robots Exclusion Protocol
Why is the public record empty?
It publishes nothing below eight graded sites, and naming a host on it needs two things at once: its tier reproduced by hand from a different network than the one that measured it, recorded against that exact tier and rubric version, and this page's publishing switch turned on. A later audit that moves the tier, or a rubric-version bump, silently un-names the host. Every audit in it ran because an owner asked, so it is a fact about that sample and not about the web.
The open record
Every tier measured this way sits in the open record, which lists nothing until eight sites have been graded — a floor against small-sample noise. Naming a host there needs two things at once: its tier reproduced by hand from a different network than the one that measured it, recorded against that exact tier and rubric version, and the page’s own publishing switch turned on. A later audit that moves the tier, or a rubric-version bump, silently un-names it again.
Removal
If a site appears in the open record and its owner would rather it did not, an email from an address at that domain to [email protected] is enough; nobody is asked to explain why, and it is not asked twice. Disallowing CiteFilesBot in robots.txt stops the audit itself from reading a site at all, for every path it would otherwise touch.
The full rubric — how each cell is measured, the five states a cell can land in, and the watch items we record but never grade — is at the methodology page. MCP and CI wiring for running this alongside the citation checks is at integrations.
Try it on your own site
Free, and the Citation Readiness summary needs no account. Sign in and open a report to ask for the Agent Commerce Readiness tier on a site you own.
Last reviewed . Maintained by Cite Files — corrections to [email protected].