Skip to content
Cite Files

Agent Commerce Readiness

Can an AI agent transact with a site — not just read it, but authenticate without borrowing a human’s password, discover an API, read a price, obtain a credential of its own?

What it asks

Citation Readiness asks whether an AI assistant can reach, read and cite a site. This is a different question, run on the same scan: whether an AI agent could act on it. There is no score, on purpose. The capability matrix is the ground truth — eight cells, each a reproducible fact about what a server said to us — and the tier is a name for a bundle of those facts, decided by published predicates rather than a judgement call.

It runs only when the owner of a scan asks for it, never affects the Citation Readiness score, and no language model is consulted anywhere in it.

What we check

The same eight cells the matrix and the public index read, so this list can never describe a check differently than the one that actually ran.

The tiers

The tier is the highest rung whose predicates are all proven true. An unknown cell stops the climb there and is not counted against a site — nobody reaches a tier through a cell we could not read, and it never denies one either.

TierPredicate
T0 · Not agent-readableAgents are refused the commerce pages, or no price is readable without running the page.
T1 · Agent-readableAn agent gets the commerce page, and the prices are text the server sent.
T2 · Agent-operableAn unauthenticated API request is answered with something a machine can act on (rate-limit headers, a machine-readable error, or a structured JSON answer), and what robots.txt says about agents agrees with what the edge does.
T3 · Agent-integratableA real machine interface exists — a parseable OpenAPI document, a live MCP endpoint, or a valid UCP manifest. Any one.
T4 · Agent-transactableAn agent can obtain its own credentials — client_credentials declared explicitly, or dynamic client registration.
T5 · Agent-payableThe site answers with a machine-payable challenge — x402 (v1 or v2) or L402 — so an agent that holds credentials could settle without a human. We observe the challenge; we never settle it.
UngradedNot a tier: the browser baseline itself was refused, so nothing could be compared. A site we could not measure has not earned a grade; it has produced no evidence.

Sources: x402 payment protocol · L402: Lightning HTTP 402 protocol

DIVERGENT

A site can serve an agent a real commerce page whose price or title differs from what a browser sees at the same URL — silent wrongness, because nothing signals it, and an agent quoting the page quotes a number the human next to it never saw. That site is still served, so it can still climb the ladder: DIVERGENT is raised beside the tier, with both sets of prices shown, and the reader judges. It never moves the tier itself.

What we never do

  • Structured receipts: they sit behind a completed transaction, and we never transact.
  • The OpenAI/Stripe Agentic Commerce Protocol and Google's AP2: both describe exchanges between parties who have already agreed to trade, and leave no server-side artefact a GET request can see.
  • Anything that needs a login we have no credential for. When you give a scan a staging basic-auth username and password, it is reused for ACR requests to that scan's own origin only — never sent to any other host a probe discovers — and we still cannot reach a login only a human browser session establishes.

It never submits a form and never attempts a payment of any kind, and it sends never more than 40 read-only requests against a site, usually well under that, honouring robots.txt for every path it touches.

How to run it

Only the signed-in owner of a scan can run it, from that scan’s report page, and only by choosing to — it never runs on its own. A commerce page can be declared by hand there if it sits somewhere our scanner would not otherwise recognise (something other than a URL containing pricing, plans or price), and that declared page is used in place of a guess.

One audit is stored per scan; running it again means declaring a different commerce page, which clears the stored result, or starting a new scan of the site.

Check a predicate yourself

Request a pricing page as a browser, then again with an AI agent’s published user-agent string, and compare status, size and whether the price survived:

curl -sI -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36" https://example.com/pricing

curl -sI -A "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" https://example.com/pricing

Fetch the OAuth authorization-server metadata document and read what it declares. RFC 8414 says an absent grant_types_supported array defaults to authorization_code and implicit — so client_credentials has to be listed explicitly for a machine to know it can authenticate without a human’s browser session:

curl -s https://example.com/.well-known/oauth-authorization-server | jq '.grant_types_supported'

A live MCP endpoint answers a plain GET with 405, because the spec is streamable-HTTP-only over POST; anything else — 200, 404, a redirect — means there is no MCP endpoint there by the spec’s own definition:

curl -si https://example.com/mcp

Questions

What is Agent Commerce Readiness?

A second audit on the same scan. The Citation Readiness score asks whether an AI assistant can reach, read and cite a site; this asks whether an AI agent could transact with it. Eight read-only checks are bundled into a tier, T0 up to T5, by published predicates. There is no score, on purpose.

Does it change my Citation Readiness score?

No. It has its own rubric version, its own table and its own predicates, and nothing in it feeds the score. Running it moves no number anywhere.

Who can run it, and does it run on its own?

Only the signed-in owner of a scan, from the report page, and only when they ask. It never runs automatically on a site.

What does it do to my server?

Never more than 40 read-only requests, usually well under that. It honours your robots.txt for every path, sends exactly one POST (an MCP server/discover, and only after a GET has answered 405), and never submits a form or a payment.

Sources: Model Context Protocol specification (2026-07-28) · RFC 9309: Robots Exclusion Protocol · Model Context Protocol specification

What do the tiers mean?

T0 Not agent-readable, T1 Agent-readable, T2 Agent-operable, T3 Agent-integratable, T4 Agent-transactable, T5 Agent-payable — each rung a bundle of reproducible facts decided by a published predicate, checkable with curl; the full predicate for each is on the methodology page. Ungraded is not a tier: it means the browser baseline itself was refused or a first-rung cell could not be read, so nothing could be compared.

Is Ungraded a bad grade?

No. Ungraded is not a tier. It means the browser baseline itself was refused or a first-rung cell could not be read, so nothing could be compared. A site we could not measure has produced no evidence, and T0 is a claim we only make when we looked and found agents refused or prices illegible.

What does citefiles.com grade on its own rubric?

T0, Not agent-readable. Our pricing page is /pro, and it carries no price yet — it describes a product that is not for sale — so the first rung fails honestly: the page was found, read as a browser and as each agent, and no price appears in it. Our MCP endpoint answers 405 to a GET and describes itself to a server/discover request, so T3's interface predicate would be met, but the ladder is climbed rung by rung and T1 is not. Until this build the same site read Ungraded, because the scanner only recognised a pricing page by the words pricing, plans or price in its path; the changelog records the change.

Sources: Model Context Protocol specification (2026-07-28) · Model Context Protocol specification · MCP specification: transports

What is DIVERGENT?

A site can serve an agent a real commerce page whose price or title differs from what a browser sees at the same URL. That site is still served, so it can still climb the ladder; the flag is raised beside the tier with both sets of prices shown, and the reader judges. It never moves the tier.

Does it test whether an agent can actually pay?

No — we never settle a challenge. T5 means the site ANSWERS with a machine-payable challenge (x402 or L402) that a credentialed agent could settle; that is an offer we can see with one request, not a transaction. Cloudflare's pay-per-crawl and a bare 402 with no machine-readable challenge stay recorded as watch items, never graded, and completing a trade leaves nothing a GET can see.

Sources: x402 payment protocol · L402: Lightning HTTP 402 protocol

What are UCP, MCP, OpenAPI and x402, in one line each?

UCP is a public manifest at /.well-known/ucp describing a merchant's agent-commerce services. MCP is the Model Context Protocol, an endpoint that answers 405 to GET and describes itself to one server/discover request. OpenAPI is a JSON description of an HTTP API with an openapi or swagger key. x402 (v1 or v2) is an HTTP 402 carrying a machine-readable challenge in a header that a credentialed agent could settle without a human; L402 is the same idea over a Lightning macaroon. We record the challenge shape and grade it at T5; we never settle one.

Sources: Model Context Protocol specification (2026-07-28) · Universal Commerce Protocol · Model Context Protocol specification · MCP specification: transports · OpenAPI Specification 3.1.0 · x402 payment protocol · L402: Lightning HTTP 402 protocol

How do I check a predicate myself?

Every predicate is a curl. Request your pricing page with a browser user-agent and again with an agent's published user-agent string and compare status, size and title. Fetch /.well-known/oauth-authorization-server and read grant_types_supported: client_credentials must appear explicitly, because the RFC 8414 default excludes it. GET your MCP path and expect 405; anything else is not an MCP endpoint by the spec.

Sources: RFC 8414: OAuth 2.0 Authorization Server Metadata · MCP specification: transports

Why is the T2 rung about robots.txt at all?

Because robots.txt is what a site says about agents and the edge is what it does, and the two are allowed to disagree. A robots.txt that allows agents while the edge challenges them is a contradiction, and only the enforced one is what an agent meets. Coherent-closed is honest and fails T2 honestly.

Sources: RFC 9309: Robots Exclusion Protocol

How do I remove my site, or stop the check running?

Write to [email protected] from an address at that domain and we remove it without asking why. To stop the check reading your site, disallow CiteFilesBot in robots.txt; the audit honours it for every path.

Sources: RFC 9309: Robots Exclusion Protocol

Why is the public record empty?

It publishes nothing below eight graded sites, and naming a host on it needs two things at once: its tier reproduced by hand from a different network than the one that measured it, recorded against that exact tier and rubric version, and this page's publishing switch turned on. A later audit that moves the tier, or a rubric-version bump, silently un-names the host. Every audit in it ran because an owner asked, so it is a fact about that sample and not about the web.

The open record

Every tier measured this way sits in the open record, which lists nothing until eight sites have been graded — a floor against small-sample noise. Naming a host there needs two things at once: its tier reproduced by hand from a different network than the one that measured it, recorded against that exact tier and rubric version, and the page’s own publishing switch turned on. A later audit that moves the tier, or a rubric-version bump, silently un-names it again.

Removal

If a site appears in the open record and its owner would rather it did not, an email from an address at that domain to [email protected] is enough; nobody is asked to explain why, and it is not asked twice. Disallowing CiteFilesBot in robots.txt stops the audit itself from reading a site at all, for every path it would otherwise touch.

The full rubric — how each cell is measured, the five states a cell can land in, and the watch items we record but never grade — is at the methodology page. MCP and CI wiring for running this alongside the citation checks is at integrations.

Try it on your own site

Free, and the Citation Readiness summary needs no account. Sign in and open a report to ask for the Agent Commerce Readiness tier on a site you own.

3 free checks a day, no account needed. Takes about a minute — a free account raises it to 25 and keeps your reports.

Last reviewed . Maintained by Cite Files — corrections to [email protected].