clerk.com/docs/reference/backend-api
Finalizing the report
Preparing the stored Is Agentic score
clerk.com/docs/reference/backend-api
Preparing the stored Is Agentic score
clerk.com/docs/reference/backend-api
These checks describe whether an ordinary agent can enter, read, and operate the public site.
Agents can reach the site
Crawler access and bot defenses.
Core content is available
Useful content remains accessible without a fragile browser-only path.
Navigation fails safely
Redirects and missing pages give agents a recoverable path.
Controls are understandable
Forms and interactive controls expose usable names and structure.
The public website is always evaluated. Optional surfaces appear when the scan finds positive evidence that they apply.
Strong
Weighted across 16 applicable checks
Ready with gaps
Weighted across 12 applicable checks
Needs work
Weighted across 3 applicable checks
Ready with gaps
Weighted across 1 applicable check
Critical access gaps come first, followed by other applicable readiness gaps.
Keep the correct HTTP 404 status. The remaining requirement is a Markdown error body when agents request Accept: text/markdown. Include at least 20 characters explaining the error and a link to your docs, sitemap, or llms.txt. Verify with curl -sS -L -i -H 'Accept: text/markdown' https://yourdomain.com/some-path-that-does-not-exist. Check both the final 404 status and the Markdown body with Content-Type: text/markdown. Checking the status alone does not verify the missing requirement.
Serve at least 500 characters of meaningful homepage content in raw HTML. Add a clear H1, keep deeper heading levels sequential, and remove excessive non-content markup.
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
Define typed JSON response schemas for every endpoint in your OpenAPI spec. Agents rely on these to know what fields they will get back; missing or partial schemas force trial-and-error.
Checks are grouped by relevance for App sites.
8337 chars with H1, but 1.0% content ratio is below the 5% target
How to pass
Serve at least 500 characters of meaningful homepage content in raw HTML. Add a clear H1, keep deeper heading levels sequential, and remove excessive non-content markup.
Site accessible to 6 AI agent user-agents
No meta-refresh stubs, JavaScript-redirect stubs, or cross-domain hops across 6 checked pages
All 5 sampled pages are publicly readable (5 with substantive content)
OpenAPI spec found at https://clerk.com/openapi.json (version: 3.0.3)
Canonical URL serves text/markdown and text/html via Accept negotiation with Vary: Accept
OAuth authorization server metadata at https://clerk.clerk.com
OpenAPI declares security schemes but no named OAuth scopes - agents get all-or-nothing access. Declare per-scope grants (e.g. read:*, write:*) in the spec.
How to pass
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
API returns JSON error responses (401 at https://api.clerk.com/v1 (from OpenAPI servers))
The nonexistent path https://clerk.com/__ora-404-probe-k8p6b7zj correctly returns HTTP 404. Partial credit: no Markdown error body was detected.
How to pass
Keep the correct HTTP 404 status. The remaining requirement is a Markdown error body when agents request Accept: text/markdown. Include at least 20 characters explaining the error and a link to your docs, sitemap, or llms.txt. Verify with curl -sS -L -i -H 'Accept: text/markdown' https://yourdomain.com/some-path-that-does-not-exist. Check both the final 404 status and the Markdown body with Content-Type: text/markdown. Checking the status alone does not verify the missing requirement.
Agent discovered 2 developer-resource types by name (API docs, auth docs) across 6 pages
clerk.com ranks #2 for "Clerk authentication"
Valid sitemap found at https://clerk.com/sitemap.xml with 3351 entries
Rich JSON-LD identity: Organization with name, description, url, and sameAs/logo/address (2 blocks)
Pricing page found at /pricing
Documentation site found at https://clerk.com
Agent instruction file at /.well-known/agent-skills/ but no explicit when-to-use guidance
How to pass
Tell agents when to reach for you: add a 'when to use this' section to your llms.txt (or a dedicated agent-instructions file) that names your best-fit use cases and how an agent should call you. Be specific about the jobs you are right for - generic marketing copy does not read as guidance.
All metadata signals present: canonical URL, lang="en", og:image, og:type
Organization schema complete with contactPoint and address
All trust anchor pages verified: About, Contact, Privacy
All 7 measured pages fit an agent context budget (largest ~6K tokens)
Code fences balanced across 1 markdown document
Developer portal found at /docs
REST API documentation found at https://clerk.com/docs/templates.md. GraphQL endpoint at https://api.clerk.com/v1/graphql is reachable; introspection requires authentication (API key / OAuth), which is expected for agent access. Best-of-protocols score: 7/7.
Onboarding signals described but not verified live: free tier available, self-serve key generation, sandbox/test environment
How to pass
Offer a free tier or trial, self-serve API key generation, and a sandbox environment. Agents can't fill out 'contact sales' forms.
MCP server detected at https://mcp.clerk.com/mcp; it requires authentication. Presence is verified (5/6), but Ora could not inspect its tools or verify access scopes without credentials.
How to pass
Keep authentication enabled. Verify tool listing with an authorized MCP client. This unauthenticated scan cannot establish whether protected tools are missing or unusable.
No REST rate-limit headers found on probed endpoints (GraphQL signal: fail 0).
How to pass
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
Partial typed error model: error schema defined but not consistently referenced (or vice versa)
How to pass
Document your error responses in your OpenAPI spec: give 4xx and 5xx responses a typed error schema (or use RFC 9457 application/problem+json). A consistent error object with a machine-readable code and a human-readable message lets agents handle failures without guessing.
API versioning strategy found (URL versioning) with sunset/deprecation markers documented
CLI package found on npm: clerk
Only 9% of operations define typed response schemas - agents cannot predict response shapes
How to pass
Define typed JSON response schemas for every endpoint in your OpenAPI spec. Agents rely on these to know what fields they will get back; missing or partial schemas force trial-and-error.
REST: agent-friendly schema (256 operations, 100% with operationIds, 100% documented by description or summary) | GraphQL: introspection auth-gated and no schema evidence in docs | Combined score: 1/2
How to pass
Make your API spec self-describing: a unique operationId and a description on every operation, typed parameters, and response schemas. For GraphQL, a fully typed schema with a documented cost or rate limit reads best.
Compatible: 256/256 ops with IDs, 244/256 with typed schemas
Verified in 2 registries: Smithery (clerk) [verified-curation], npm (@clerk/mcp-tools) [package-owner] - 407 agent uses, verified
NPM package found: @clerk/clerk-sdk-node - "Clerk server SDK for usage with node"
MCP manifest has name and description but no icon at /.well-known/mcp/server-card.json
How to pass
Give your MCP server-card (at /.well-known/mcp/server-card.json) a display name, an icon or logo, and a description - all three together are what reads as a complete, branded listing agents can present.
Found in ChatGPT app directory: "Clerk"
Agent Skills index (agentskills.io) found at /.well-known/agent-skills/index.json with 20 skill(s)
Index v0.2.0 conformant; verified SHA-256 of "clerk" (skill-md); 19 other skills present; not fetched
24 official skills published on skills.sh - 571,988 total installs (skills.sh/clerk)
Structured pricing.md found at /pricing.md (263 lines)
MCP server discoverable via server-card.json at /.well-known/mcp/
Partial markdown fallback support. Homepage (https://clerk.com/index.md) returns markdown, but 1 of 3 sampled content pages do not: https://clerk.com/agents.md. To earn full credit, serve a .md twin for each content page (e.g. /docs/auth -> /docs/auth.md) with text/markdown content-type or a heading-led non-HTML body.
How to pass
Let agents fetch markdown by appending .md to page URLs. Required for any credit: serve a markdown homepage at /index.md. For full credit (2/2): also serve a .md twin for each content page (e.g. /docs/auth -> /docs/auth.md). Content-Type should be text/markdown and the body should start with a top-level heading (not HTML).
100% of 500 sampled sitemap entries carry lastmod; newest is 2 day(s) old
Found the llms.txt at https://clerk.com/llms.txt.
The llms.txt is well-formatted with markdown links, but at 558,480 characters it exceeds the 30,000-character recommendation for a navigation index.
How to pass
Format your llms.txt as a navigation index: start with a markdown heading, include markdown links to deeper resources, and keep it under 30,000 characters. If you have more to say, move long-form content into /llms-full.txt or per-section files (e.g. /docs/llms.txt, /api/llms.txt) and link to them from the main index.
Rich skills.sh presence - 24 skills, 571,988 installs. Agents can understand capabilities in depth
Strong entity linking via sameAs: github.com, linkedin.com
All 5 probed llms.txt links resolve to real content
api-catalog linkset[0] has no 'item' entries
How to pass
Publish an API catalog at /.well-known/api-catalog per RFC 9727. Serve it with Content-Type: application/linkset+json;profile="https://www.rfc-editor.org/info/rfc9727" and include a 'linkset' array with item entries pointing to your OpenAPI specs and service descriptions.
Path-suffix markdown docs served with text/markdown content-type: /index.md
product MCP requires authentication with OAuth metadata discovery
RFC 8414 OAuth metadata for product MCP: issuer=https://clerk.clerk.com, auth and token endpoints present; client registration: CIMD (client_id_metadata_document_supported)
OAuth metadata for product MCP supports PKCE S256 code challenge
RFC 9728 metadata at https://mcp.clerk.com: resource=https://mcp.clerk.com/mcp, authorization_servers (1), scopes_supported (7)
PRM + AS metadata both present (PRM discovered at https://mcp.clerk.com) (AS metadata fetched from advertised origin https://clerk.clerk.com) but AS metadata has no agent_auth block
How to pass
Publish RFC 9728 protected-resource metadata at /.well-known/oauth-protected-resource on your resource server (the host that actually serves the API, e.g. api.<apex>) with resource and authorization_servers. Publish RFC 8414 authorization-server metadata at /.well-known/oauth-authorization-server on the AS origin, and include the WorkOS auth.md agent_auth block with identity_endpoint, identity_types_supported drawn from the spec enum (anonymous, identity_assertion, service_auth - the assertion variant, the ID-JAG URN urn:ietf:params:oauth:token-type:id-jag, belongs inside identity_assertion.assertion_types_supported, not at the top level), and the identity_assertion.assertion_types_supported block when you advertise that type, so agents can check their assertion shape is accepted before minting. Cross-link by listing the AS origin in PRM authorization_servers, and point agent_auth.skill back at your published /auth.md. Spec: https://github.com/workos/auth.md.
401 at https://mcp.clerk.com at /mcp with spec-shaped WWW-Authenticate hint: Bearer resource_metadata="https://mcp.clerk.com/.well-known/oauth-protected-resource/mcp", scope="user:org:read applicat
WebMCP mentioned in documentation at /docs but not implemented on homepage
How to pass
Expose in-page tools through WebMCP, a proposed web standard for browser agents. Register tools with document.modelContext.registerTool() and use navigator.modelContext only as a trailing compatibility fallback. Declarative forms with toolname and tooldescription provide server-rendered evidence, but remain a preview and should not be your only tool surface. Chrome's origin trial covers versions 149-156, with shipping currently targeted for 157. ChatGPT can discover and call WebMCP site tools in the desktop app's built-in browser when the feature is available.
Cursor-based pagination found in OpenAPI spec response schemas or query parameters
202 Accepted responses found alongside a job-style path (/jobs, /operations, /tasks, /async, or {id}/status) but the 202 itself carries no Location header or job-tracking fields
How to pass
For long-running operations, return 202 Accepted and point agents at where to poll for the result (a status/location reference plus a job identifier in the body), documented in your OpenAPI spec, so work that does not finish in one request is still followable.
SDK packages found in npm, rubygems
How to pass
Publish official SDK packages across multiple language ecosystems (npm, PyPI, Go modules, RubyGems). Auto-generate them from your OpenAPI spec using tools like openapi-generator. For each package set the project URL or homepage to your product domain (package.json repository/homepage, PyPI Home-Page or project_urls, RubyGems homepage_uri) - this is how agents verify the package is your official SDK.
MCP server card found at https://clerk.com/.well-known/mcp/server-card.json but missing fields: version
How to pass
Publish a server card for each MCP server (draft MCP server-card extension). List each card in /.well-known/ai-catalog.json, or serve it at <server URL>/server-card. /.well-known/mcp/server-card.json is still read for a site with one server, but the extension does not recommend it. Include name, description, and version, and put the server's exact address in remotes[].url (serverUrl is also read) so agents match each card to the right server before connecting. Follow the extension schema for full credit: $schema set to https://static.modelcontextprotocol.io/schemas/v1/server-card.schema.json, a reverse-DNS name such as com.example/mcp, and no tools[] (agents always trust the live tools/list). Keep the description to 100 characters or fewer, as the schema requires. A card without that $schema is still read, and then an optional tools[] list completes it.
Batch operation found: POST/PUT endpoint accepts array request body in OpenAPI spec
Server HTML is a well-structured document (main=true, landmarks=4/4, h1=1, maxHeadingSkip=1).
87 native controls, 1 non-native div-soup affordances (99% native).
87/87 interactive elements have a computable accessible name (100%).
10/10 form controls have an associated label (100%).
No hidden instruction text detected in accessibility-tree attributes or off-screen content.
What does clerk.com do and who is it for? Explain it back to me.
Sign me up for Vercel product updates and marketing emails.
Unsubscribe anytime. Privacy Notice
Source: Ora API
What does clerk.com do and who is it for? Explain it back to me.
14 steps6 reasoning steps3 searches
The agent successfully understood Clerk's core offering, pricing model, and competitive differentiation, but relied almost entirely on web search results and prior knowledge rather than Clerk's own site content. The site itself was largely untraversable via direct HTML fetching—the agent could not extract meaningful structured information from the homepage, pricing page, or documentation, forcing it to reconstruct the answer from third-party comparison articles and pre-existing knowledge.