Skip to main content
The Agent Discoverability scanner tests one public domain. It checks whether agent systems can reach, identify, and find the product’s official public surfaces. The scan is a static audit. It does not run Claude, Codex, or another live agent. It does not measure whether an agent selects the product during a task.

How the scan works

  1. We normalize the submitted domain and require public HTTPS.
  2. We read the homepage, robots rules, sitemap, selected documentation pages, and public discovery files.
  3. We check supported public registries and directories.
  4. We run two Exa searches. One searches for the brand. One searches for official developer resources.
  5. We evaluate the same 45 deterministic tests against the collected evidence.
We do not assign a score or grade. The report shows the full result mix and the actions that can improve discoverability.

Result meanings

Agent access and indexability

These 22 tests check whether agent systems can reach and read official public content.

Agent-facing distribution surfaces

These 21 tests check whether the product appears where agents and developers look for tools. Surface-specific tests become Not applicable when the product does not advertise that surface.

Agent-oriented search presence

These two tests use Exa as an agent-oriented search index. Each search stores at most 10 result rows with URL, title, and an identity verdict. The scan does not generate category queries, problem queries, comparison queries, or agent selection experiments. Those are separate Agent Discoverability runs.

Recommendations

Every warning and failure includes a direct action. The report ranks the most important actions first. It also keeps the complete test table so you can inspect the result, evidence, and action for each test.

Cache and public results

A completed result stays fresh for exactly 24 hours. A repeat scan during that period returns the same result and starts no new work. An expired result stays idle until a user submits the domain again. Completed results can appear in the public recent-results list. The scanner does not publish failed runs, internal IDs, request identifiers, raw provider records, or scanner secrets.

Safety limits

The scanner makes read-only requests to public HTTPS resources. It blocks private, local, link-local, metadata, and other prohibited IP ranges. It rechecks DNS and every redirect to prevent rebinding. Requests have strict limits for time, redirects, response bytes, decompression, and total request count. The scanner never sends target credentials. It does not create accounts, make purchases, or call state-changing MCP tools.