Results for https://stripe.com/LEVEL1Scanned just now
21/100
Basic Web Presence
Discoverability
50
2 pass · 2 fail
Content Accessibility
0
0 pass · 1 fail
Bot Access Control
50
1 pass · 1 fail
Discovery
0
0 pass · 7 fail
Commerce
0
0 pass · 4 fail
02 / 04 pass
Discoverability
- Goal
- Publish a robots.txt so agents and crawlers can discover crawl policy for this origin.
- How to implement
- Create /robots.txt on this origin with at least one User-agent group and sensible Allow/Disallow rules. Serve it as text/plain.
- Resources
- fetchGET /robots.txt200
Sitemap: https://stripe.com/sitemap/sitemap.xml User-agent: ia_archiver Allow: /docs/api Allow: /docs/api$ Disallow: /docs Disallow: /docs$ Disallow: /bitcoin/refund Disallow: /sources/refund Disallow: /sources/sepa_mandate Disallow: /sources/test_source Disallow: /sources/test_klarna Disallow: /handoff-healthcheck Disallow: /handoff User-agent: * Allow: /docs Allow: /docs$ Disallow: /bitcoin/refund Disallow: /sources/refund
- concluderobots.txt present with User-agent directive
{"contentType":"text/plain; charset=utf-8"}
- Goal
- Expose a valid XML sitemap so agents can enumerate important URLs.
- How to implement
- Add a valid XML sitemap and reference it with a Sitemap: line in robots.txt (or serve /sitemap.xml).
- Resources
- fetchGET /sitemap/sitemap.xml200
<?xml version="1.0" encoding="UTF-8"?><sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <sitemap> <loc>https://stripe.com/sitemap/partition-0.xml</loc></sitemap><sitemap> <loc>https://stripe.com/sitemap/partition-1.xml</loc></sitemap><sitemap> <loc>https://stripe.com/sitemap/partition-2.xml</loc></sitemap><sitemap> <loc>https://stripe.com/sitemap/partition-3.xml</loc></sitemap><sitemap> <loc>https://stripe.com/sitemap/partition-4.xml</loc></sitemap><sitemap> <…
- parseValid XML sitemap structure detected
- concludeSitemap OK at https://stripe.com/sitemap/sitemap.xml
{"url":"https://stripe.com/sitemap/sitemap.xml"}
- Goal
- Advertise agent-useful Link relations on the homepage so discovery is machine-readable.
- Issue
- Homepage has no Link header
- How to implement
- Add RFC 8288 Link response headers on GET / for agent-useful relations such as api-catalog, describedby, service-desc, or service-doc.
- Resources
- fetchGET /200
- concludeNo Link header on homepage
- Goal
- Publish DNS-AID SVCB records under _agents so agents can find services via DNS.
- Issue
- No DNSSEC-validated DNS-AID SVCB/HTTPS/TXT ServiceMode records found
- How to implement
- Publish DNSSEC-validated SVCB/HTTPS records for _index._agents, _mcp._agents, and/or _a2a._agents on the apex (and www if used).
- Resources
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- concludeNo DNSSEC-validated (AD=true) ServiceMode DNS-AID records
00 / 01 pass
Content Accessibility
- Goal
- Serve text/markdown when clients Accept: text/markdown so agents can read a clean page summary.
- Issue
- Homepage does not return text/markdown for Accept: text/markdown
- How to implement
- When GET / is requested with Accept: text/markdown, respond with Content-Type including text/markdown (e.g. Cloudflare Markdown for Agents or an equivalent).
- Resources
- fetchGET /200
<!DOCTYPE html><html id="" lang="en-US"><head><meta charSet="utf-8"/><meta name="edge-experiment-treatments" content="wpp_react_homepage_aa.treatment.ursula.58a7d8f8-a2fe-9a8b-40b4-5fd361709a1c.a.s,wpp_acquisition_mobile_sticky_hamburger.control.ursula.4fd32132-b507-5f3c-fec0-89b824353165.m.s,wpp_console_mvp_nav_cta.control.ursula.a3d7f5ce-7950-3fdf-edb2-b9602ac76f21.m.s,acquisition_chat_cta.treatment.ursula.c7f6516c-bd5e-67ea-445f-7c819677b10d.a.s"/><meta name="experiment-treatments" content="…
- concludeNo markdown negotiation (content-type=text/html; charset=utf-8)
{"status":200,"contentType":"text/html; charset=utf-8"}
01 / 03 pass
Bot Access Control
- Goal
- Declare AI crawler rules in robots.txt so bot access policy is explicit.
- How to implement
- Add explicit User-agent rules for known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, etc.) or a clear User-agent: * policy in robots.txt.
- Resources
- parseParsed 3 user-agent group(s)
- concludeFound AI crawler rules or User-agent: * policy
- Goal
- Publish Content-Signal directives so AI training/search/input preferences are machine-readable.
- Issue
- robots.txt missing Content-Signal ai-train/search/ai-input directives
- How to implement
- Add Content-Signal: lines in robots.txt with ai-train / search / ai-input directives stating your preferences for AI use of the site.
- Resources
- parseContent-Signal lines: 0
- concludeNo Content-Signal directives with ai-train/search/ai-input
- Goal
- Publish an HTTP Message Signatures directory so bots can authenticate cryptographically.
- How to implement
- Serve a valid JWKS directory at /.well-known/http-message-signatures-directory for cryptographic bot authentication.
- Resources
- fetchGET /.well-known/http-message-signatures-directory404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeDirectory missing or invalid — reporting neutral
{"status":404}
00 / 08 pass
Discovery
- Goal
- Publish an RFC 9727 API catalog so agents can discover your API surfaces.
- Issue
- api-catalog not found
- How to implement
- Serve /.well-known/api-catalog as application/linkset+json with a linkset array describing your API surfaces.
- Resources
- fetchGET /.well-known/api-catalog404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeHTTP 404
- Goal
- Publish OAuth/OIDC discovery metadata so agents can authenticate with your APIs.
- Issue
- No OAuth/OIDC discovery metadata with issuer + auth/token endpoints
- How to implement
- Serve /.well-known/openid-configuration or /.well-known/oauth-authorization-server with issuer, authorization_endpoint, and token_endpoint.
- Resources
- fetchGET /.well-known/openid-configuration404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchGET /.well-known/oauth-authorization-server404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeNo valid OAuth/OIDC discovery document
- Goal
- Publish OAuth protected resource metadata so agents know which auth servers protect your API.
- Issue
- oauth-protected-resource missing resource + authorization_servers
- How to implement
- Serve /.well-known/oauth-protected-resource with resource and authorization_servers, and advertise it via WWW-Authenticate where relevant.
- Resources
- fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludePRM missing or incomplete
- Goal
- Publish /auth.md so agents have human-readable registration and auth guidance.
- Issue
- Need auth.md plus discoverable PRM or agent_auth, with registration methods documented
- How to implement
- Serve /auth.md as text/markdown documenting how agents register/authenticate, discoverable via PRM and/or AS metadata agent_auth.
- Resources
- fetchGET /auth.md404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__captured… - parseauthMd=false prm=false agent_auth=false registrationDocs=true
- concludeauth.md discovery incomplete
{"authOk":false,"prmOk":false,"agentAuth":false,"mentionsRegistration":true}
- Goal
- Publish an MCP server card and reachable Streamable HTTP endpoint so agents can list tools.
- Issue
- No MCP server card (serverInfo.name/name) or live Streamable HTTP endpoint
- How to implement
- Publish /.well-known/mcp/server-card.json (or mcp.json) with serverInfo.name, and expose a Streamable HTTP MCP endpoint that answers initialize + tools/list.
- Resources
- fetchGET /.well-known/mcp.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchGET /.well-known/mcp/server-cards.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchGET /.well-known/mcp/server-card.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchPOST /api/mcp/mcp404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeNo MCP card or live endpoint
- Goal
- Publish an A2A agent card so agents can discover your A2A interface.
- How to implement
- Serve /.well-known/agent-card.json with name, version, and supportedInterfaces per the A2A Agent Card spec.
- Resources
- concludeCheck disabled for this scan
- Goal
- Publish an agent-skills index so agents can find skill docs for this origin.
- Issue
- No valid agent-skills index.json (v0.2 skills array)
- How to implement
- Serve /.well-known/agent-skills/index.json (v0.2) listing skills agents can use against this origin.
- Resources
- fetchGET /.well-known/agent-skills/index.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - fetchGET /.well-known/skills/index.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeNo valid agent-skills index
- Goal
- Register WebMCP tools on the homepage so headless scanners discover browser-side tools.
- Issue
- Homepage has no WebMCP tools on navigator.modelContext
- How to implement
- On page load, register at least one WebMCP tool via navigator.modelContext (provideContext/registerTool) so headless scanners can discover it.
- Resources
- fetchLaunching Browser Rendering session for WebMCP inspection
- parseCaptured 0 WebMCP tool registration(s)
- concludeNo tools recorded via provideContext/registerTool
00 / 05 pass
Commerce
- Goal
- Advertise x402 payment challenges on payable API routes so agents can pay per request.
- Issue
- No x402 402 challenge on /, /api, or /api/v1 (Bazaar not queried)
- How to implement
- Return HTTP 402 with a valid x402 payment challenge (PAYMENT-REQUIRED / payment required body) on payable API routes such as /api/v1.
- Resources
- concludeCoinbase Bazaar discovery not queried (skipped in v1 scanner)
- fetchGET /200
<!DOCTYPE html><html id="" lang="en-US"><head><meta charSet="utf-8"/><meta name="edge-experiment-treatments" content="wpp_react_homepage_aa.treatment.ursula.ee05b5cb-afe7-0b2a-433c-e52899c969d6.a.s,wpp_acquisition_mobile_sticky_hamburger.control.ursula.b0793c36-1c39-5cd8-78f6-21be560c85ef.m.s,wpp_console_mvp_nav_cta.treatment.ursula.306c2ba9-0dfb-f677-c351-229536e0d04b.m.s,acquisition_chat_cta.treatment.ursula.24640e9d-4080-1a8a-3273-b2803146f2f0.a.s"/><meta name="experiment-treatments" content…
- fetchGET /api301
- fetchGET /api/v1404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeNo 402 x402 challenge found
- Goal
- Declare Machine Payments Protocol extensions in OpenAPI so payable ops are discoverable.
- Issue
- openapi.json not found
- How to implement
- Serve /openapi.json with x-payment-info extensions describing payable operations.
- Resources
- fetchGET /openapi.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeHTTP 404
- Goal
- Publish Universal Commerce Protocol metadata for agent commerce discovery.
- Issue
- UCP metadata not found
- How to implement
- Serve /.well-known/ucp with protocol_version and services.
- Resources
- fetchGET /.well-known/ucp404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeHTTP 404
- Goal
- Publish Agentic Commerce Protocol metadata for agent commerce discovery.
- Issue
- ACP metadata not found
- How to implement
- Serve /.well-known/acp.json with protocol name/version, api_base_url, transports, and capabilities.
- Resources
- fetchGET /.well-known/acp.json404
<!DOCTYPE html> <html class="MktRoot" lang="en-US" data-js-controller="Page" data-page-id="Not found" data-page-title="Page not found" data-loading > <head> <script>window.__capturedErrors = []; window.onerror = function (message, url, line, column, error) { __capturedErrors.push(error); }; window.onunhandledrejection = function(evt) { __capturedErrors.push(evt.reason); } </script> <meta name="sentry-config" data-js-dsn="" data-js-release="442ba97944075ccddf1e1440bb672034… - concludeHTTP 404
- Goal
- Advertise AP2 extensions on the A2A agent card for agent payment flows.
- How to implement
- Extend /.well-known/agent-card.json with an AP2 extension that declares a role.
- Resources
- concludeCheck disabled for this scan
Improve the score
Next: Level 2 — Bot-Aware
Publish Content-Signal directives in robots.txt
Next level
Level 2 — Bot-Aware