Results for https://jellycat.com/LEVEL0Scanned just now
Not Ready
Discoverability
25
1 pass · 3 fail
Content Accessibility
100
1 pass · 0 fail
Bot Access Control
50
1 pass · 1 fail
Discovery
0
0 pass · 7 fail
Commerce
0
0 pass · 4 fail
01 / 04 pass
Discoverability
- Goal
- Publish a robots.txt so agents and crawlers can discover crawl policy for this origin.
- How to implement
- Create /robots.txt on this origin with at least one User-agent group and sensible Allow/Disallow rules. Serve it as text/plain.
- Resources
- fetchGET /robots.txt200
User-agent: * Disallow: /account.php Disallow: /cart.php Disallow: /checkout.php Disallow: /checkout Disallow: /finishorder.php Disallow: /login.php Disallow: /orderstatus.php Disallow: /postreview.php Disallow: /productimage.php Disallow: /productupdates.php Disallow: /remote.php Disallow: /search.php Disallow: /viewfile.php Disallow: /wishlist.php Disallow: /admin/ Disallow: /__socialshop/ Disallow: /jellycat-gift-card/ Disallow: /jellycat-gift-box/ Disallow: /blog
- concluderobots.txt present with User-agent directive
{"contentType":"text/plain; charset=UTF-8"}
- Goal
- Expose a valid XML sitemap so agents can enumerate important URLs.
- Issue
- No valid XML sitemap found via robots.txt or /sitemap.xml
- How to implement
- Add a valid XML sitemap and reference it with a Sitemap: line in robots.txt (or serve /sitemap.xml).
- Resources
- fetchInvalid URL: /xmlsitemap.php
- fetchGET /sitemap.xml404
<!DOCTYPE html> <html class="no-js" lang="en"> <head> <script> const srcUrl = 'NxTq86nk_FkN69O0mQq'; (function(g,e,o,t,a,r,ge,tl,y,s){ t=g.getElementsByTagName(o)[0];y=g.createElement(e);y.setAttribute("data-cfasync","false");y.async=true; y.src='https://g10498469755.co/gr?id=-'+srcUrl+'&refurl='+g.referrer+'&winurl='+encodeURIComponent(window.location); t.parentNode.insertBefore(y,t); })(document,'scrip… - fetchGET /sitemap_index.xml404
<!DOCTYPE html> <html class="no-js" lang="en"> <head> <script> const srcUrl = 'NxTq86nk_FkN69O0mQq'; (function(g,e,o,t,a,r,ge,tl,y,s){ t=g.getElementsByTagName(o)[0];y=g.createElement(e);y.setAttribute("data-cfasync","false");y.async=true; y.src='https://g10498469755.co/gr?id=-'+srcUrl+'&refurl='+g.referrer+'&winurl='+encodeURIComponent(window.location); t.parentNode.insertBefore(y,t); })(document,'scrip… - concludeNo valid XML sitemap found
- Goal
- Advertise agent-useful Link relations on the homepage so discovery is machine-readable.
- Issue
- Link header present but no agent-useful relations
- How to implement
- Add RFC 8288 Link response headers on GET / for agent-useful relations such as api-catalog, describedby, service-desc, or service-doc.
- Resources
- fetchGET /200
- parseParsed 2 Link entries
- concludeNo agent-useful Link relations
{"links":[{"rel":"preconnect","href":"https://cdn11.bigcommerce.com/s-e66ltxu1n1"},{"rel":"preload","href":"https://cdn11.bigcommerce.com/s-e66ltxu1n1/stencil/8ac78f80-5e0d-013f-34d8-1af6baef0f3a/e/39340920-61c5-013f-95a7-1e9c5d8d4d8b/css/theme-961511d0-68e8-013f-ea5f-5e3c25b674ac.css"}]}
- Goal
- Publish DNS-AID SVCB records under _agents so agents can find services via DNS.
- Issue
- No DNSSEC-validated DNS-AID SVCB/HTTPS/TXT ServiceMode records found
- How to implement
- Publish DNSSEC-validated SVCB/HTTPS records for _index._agents, _mcp._agents, and/or _a2a._agents on the apex (and www if used).
- Resources
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- dnsAD=false status=3 answers=0
- concludeNo DNSSEC-validated (AD=true) ServiceMode DNS-AID records
01 / 01 pass
Content Accessibility
- Goal
- Serve text/markdown when clients Accept: text/markdown so agents can read a clean page summary.
- How to implement
- When GET / is requested with Accept: text/markdown, respond with Content-Type including text/markdown (e.g. Cloudflare Markdown for Agents or an equivalent).
- Resources
- fetchGET /200
--- description: Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. --- <!DOCTYPE html> [Skip to main content](#main-content) [Discover our newest arrivals! → ](https://jellycat.com/new) Free UK delivery on orders over £50\* [Jellycat Purrks has landed - sign up today!](https://jellycat.com/jellycat-purrks/)  or a clear User-agent: * policy in robots.txt.
- Resources
- parseParsed 2 user-agent group(s)
- concludeFound AI crawler rules or User-agent: * policy
- Goal
- Publish Content-Signal directives so AI training/search/input preferences are machine-readable.
- Issue
- robots.txt missing Content-Signal ai-train/search/ai-input directives
- How to implement
- Add Content-Signal: lines in robots.txt with ai-train / search / ai-input directives stating your preferences for AI use of the site.
- Resources
- parseContent-Signal lines: 0
- concludeNo Content-Signal directives with ai-train/search/ai-input
- Goal
- Publish an HTTP Message Signatures directory so bots can authenticate cryptographically.
- How to implement
- Serve a valid JWKS directory at /.well-known/http-message-signatures-directory for cryptographic bot authentication.
- Resources
- fetchGET /.well-known/http-message-signatures-directory404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludeDirectory missing or invalid — reporting neutral
{"status":404}
00 / 08 pass
Discovery
- Goal
- Publish an RFC 9727 API catalog so agents can discover your API surfaces.
- Issue
- api-catalog not found
- How to implement
- Serve /.well-known/api-catalog as application/linkset+json with a linkset array describing your API surfaces.
- Resources
- fetchGET /.well-known/api-catalog404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludeHTTP 404
- Goal
- Publish OAuth/OIDC discovery metadata so agents can authenticate with your APIs.
- Issue
- No OAuth/OIDC discovery metadata with issuer + auth/token endpoints
- How to implement
- Serve /.well-known/openid-configuration or /.well-known/oauth-authorization-server with issuer, authorization_endpoint, and token_endpoint.
- Resources
- fetchGET /.well-known/openid-configuration404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- fetchGET /.well-known/oauth-authorization-server404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludeNo valid OAuth/OIDC discovery document
- Goal
- Publish OAuth protected resource metadata so agents know which auth servers protect your API.
- Issue
- oauth-protected-resource missing resource + authorization_servers
- How to implement
- Serve /.well-known/oauth-protected-resource with resource and authorization_servers, and advertise it via WWW-Authenticate where relevant.
- Resources
- fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludePRM missing or incomplete
- Goal
- Publish /auth.md so agents have human-readable registration and auth guidance.
- Issue
- Need auth.md plus discoverable PRM or agent_auth, with registration methods documented
- How to implement
- Serve /auth.md as text/markdown documenting how agents register/authenticate, discoverable via PRM and/or AS metadata agent_auth.
- Resources
- fetchGET /auth.md404
<!DOCTYPE html> <html class="no-js" lang="en"> <head> <script> const srcUrl = 'NxTq86nk_FkN69O0mQq'; (function(g,e,o,t,a,r,ge,tl,y,s){ t=g.getElementsByTagName(o)[0];y=g.createElement(e);y.setAttribute("data-cfasync","false");y.async=true; y.src='https://g10498469755.co/gr?id=-'+srcUrl+'&refurl='+g.referrer+'&winurl='+encodeURIComponent(window.location); t.parentNode.insertBefore(y,t); })(document,'scrip… - fetchGET /.well-known/oauth-protected-resource404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softe…
- parseauthMd=false prm=false agent_auth=false registrationDocs=true
- concludeauth.md discovery incomplete
{"authOk":false,"prmOk":false,"agentAuth":false,"mentionsRegistration":true}
- Goal
- Publish an MCP server card and reachable Streamable HTTP endpoint so agents can list tools.
- Issue
- No MCP server card (serverInfo.name/name) or live Streamable HTTP endpoint
- How to implement
- Publish /.well-known/mcp/server-card.json (or mcp.json) with serverInfo.name, and expose a Streamable HTTP MCP endpoint that answers initialize + tools/list.
- Resources
- fetchGET /.well-known/mcp.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- fetchGET /.well-known/mcp/server-cards.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- fetchGET /.well-known/mcp/server-card.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- fetchPOST /api/mcp/mcp301
- concludeNo MCP card or live endpoint
- Goal
- Publish an A2A agent card so agents can discover your A2A interface.
- How to implement
- Serve /.well-known/agent-card.json with name, version, and supportedInterfaces per the A2A Agent Card spec.
- Resources
- concludeCheck disabled for this scan
- Goal
- Publish an agent-skills index so agents can find skill docs for this origin.
- Issue
- No valid agent-skills index.json (v0.2 skills array)
- How to implement
- Serve /.well-known/agent-skills/index.json (v0.2) listing skills agents can use against this origin.
- Resources
- fetchGET /.well-known/agent-skills/index.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- fetchGET /.well-known/skills/index.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludeNo valid agent-skills index
- Goal
- Register WebMCP tools on the homepage so headless scanners discover browser-side tools.
- Issue
- Homepage has no WebMCP tools on navigator.modelContext
- How to implement
- On page load, register at least one WebMCP tool via navigator.modelContext (provideContext/registerTool) so headless scanners can discover it.
- Resources
- fetchLaunching Browser Rendering session for WebMCP inspection
- parseCaptured 0 WebMCP tool registration(s)
- concludeNo tools recorded via provideContext/registerTool
00 / 05 pass
Commerce
- Goal
- Advertise x402 payment challenges on payable API routes so agents can pay per request.
- Issue
- No x402 402 challenge on /, /api, or /api/v1 (Bazaar not queried)
- How to implement
- Return HTTP 402 with a valid x402 payment challenge (PAYMENT-REQUIRED / payment required body) on payable API routes such as /api/v1.
- Resources
- concludeCoinbase Bazaar discovery not queried (skipped in v1 scanner)
- fetchGET /200
<!DOCTYPE html> <html class="no-js" lang="en"> <head> <script> const srcUrl = 'NxTq86nk_FkN69O0mQq'; (function(g,e,o,t,a,r,ge,tl,y,s){ t=g.getElementsByTagName(o)[0];y=g.createElement(e);y.setAttribute("data-cfasync","false");y.async=true; y.src='https://g10498469755.co/gr?id=-'+srcUrl+'&refurl='+g.referrer+'&winurl='+encodeURIComponent(window.location); t.parentNode.insertBefore(y,t); })(document,'scri… - fetchGET /api404
- fetchGET /api/v1404
- concludeNo 402 x402 challenge found
- Goal
- Declare Machine Payments Protocol extensions in OpenAPI so payable ops are discoverable.
- Issue
- openapi.json not found
- How to implement
- Serve /openapi.json with x-payment-info extensions describing payable operations.
- Resources
- fetchGET /openapi.json404
<!DOCTYPE html> <html class="no-js" lang="en"> <head> <script> const srcUrl = 'NxTq86nk_FkN69O0mQq'; (function(g,e,o,t,a,r,ge,tl,y,s){ t=g.getElementsByTagName(o)[0];y=g.createElement(e);y.setAttribute("data-cfasync","false");y.async=true; y.src='https://g10498469755.co/gr?id=-'+srcUrl+'&refurl='+g.referrer+'&winurl='+encodeURIComponent(window.location); t.parentNode.insertBefore(y,t); })(document,'scrip… - concludeHTTP 404
- Goal
- Publish Universal Commerce Protocol metadata for agent commerce discovery.
- Issue
- UCP missing protocol_version + services
- How to implement
- Serve /.well-known/ucp with protocol_version and services.
- Resources
- fetchGET /.well-known/ucp200
{"ucp":{"version":"2026-04-08","services":{"dev.ucp.shopping":[{"version":"2026-04-08","transport":"rest","endpoint":"https://jellycat.com/api/ucp"}]},"capabilities":{"dev.ucp.shopping.cart":[{"version":"2026-04-08","spec":"https://ucp.dev/specification/cart","schema":"https://ucp.dev/2026-04-08/schemas/shopping/cart.json"}],"dev.ucp.shopping.checkout":[{"version":"2026-04-08","spec":"https://ucp.dev/specification/checkout","schema":"https://ucp.dev/2026-04-08/schemas/shopping/checkout.json"}],"… - parseprotocol_version=undefined services=false
- concludeInvalid UCP body
- Goal
- Publish Agentic Commerce Protocol metadata for agent commerce discovery.
- Issue
- ACP metadata not found
- How to implement
- Serve /.well-known/acp.json with protocol name/version, api_base_url, transports, and capabilities.
- Resources
- fetchGET /.well-known/acp.json404
<!DOCTYPE html> <html lang="en" dir="ltr"> <head> <title>Jellycat - Not Found</title> <meta charset="UTF-8"> <meta name="description" content="Welcome to the official online home of the softest stuffed toys. Sharing joy since 1999. Explore the collection of Loveable characters, Amuseables, and personalised gifts for all ages. " /> <meta name="keywords" content="" /> <link href="//fonts.googleapis.com/css?family=Lato:400,300" rel="stylesheet" type="text/css">
- concludeHTTP 404
- Goal
- Advertise AP2 extensions on the A2A agent card for agent payment flows.
- How to implement
- Extend /.well-known/agent-card.json with an AP2 extension that declares a role.
- Resources
- concludeCheck disabled for this scan
Improve the score
Next: Level 1 — Basic Web Presence
Expose a valid XML sitemap (via robots.txt Sitemap: or /sitemap.xml)
Advertise agent-useful Link relations on the homepage
Next level
Level 1 — Basic Web Presence