graphify.com
Finalizing the report
Preparing the stored Is Agentic score
graphify.com
Preparing the stored Is Agentic score
graphify.com
These checks describe whether an ordinary agent can enter, read, and operate the public site.
Agents can reach the site
Crawler access and bot defenses.
Core content is available
Useful content remains accessible without a fragile browser-only path.
Navigation fails safely
Redirects and missing pages give agents a recoverable path.
Controls are understandable
Forms and interactive controls expose usable names and structure.
The public website is always evaluated. Optional surfaces appear when the scan finds positive evidence that they apply.
Ready with gaps
Weighted across 17 applicable checks
Strong
Weighted across 12 applicable checks
Needs work
Weighted across 3 applicable checks
Strong
Weighted across 3 applicable checks
Critical access gaps come first, followed by other applicable readiness gaps.
Keep the correct HTTP 404 status. The remaining requirement is a Markdown error body when agents request Accept: text/markdown. Include at least 20 characters explaining the error and a link to your docs, sitemap, or llms.txt. Verify with curl -sS -L -i -H 'Accept: text/markdown' https://yourdomain.com/some-path-that-does-not-exist. Check both the final 404 status and the Markdown body with Content-Type: text/markdown. Checking the status alone does not verify the missing requirement.
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
Add Organization JSON-LD that includes both contactPoint (with email/phone and contactType) and address (PostalAddress). This lets AI verify your business legitimacy and answer contact queries.
Offer a free tier or trial, self-serve API key generation, and a sandbox environment. Agents can't fill out 'contact sales' forms.
Checks are grouped by relevance for App sites.
9483 chars, semantic headings (1 H1 + 8 H2s + 11 H3s), 8.7% content ratio
Site accessible to 6 AI agent user-agents
No meta-refresh stubs, JavaScript-redirect stubs, or cross-domain hops across 6 checked pages
All 5 sampled pages are publicly readable (5 with substantive content)
OpenAPI spec found at https://api.graphify.com/openapi.json (version: 3.1.0)
Canonical URL serves text/markdown and text/html via Accept negotiation with Vary: Accept
All major AI crawlers can reach the site: ChatGPT-User, ClaudeBot, Google-Extended, ora-agent, DeepSeekBot.
OpenID Connect discovery endpoint found at https://auth.graphify.com
OpenAPI declares security schemes but no named OAuth scopes - agents get all-or-nothing access. Declare per-scope grants (e.g. read:*, write:*) in the spec.
How to pass
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
API returns JSON error responses (404 at https://api.graphify.com)
MCP server exposes 1 resource(s) via resources/list
The nonexistent path https://graphify.com/__ora-404-probe-7kp103n5 correctly returns HTTP 404. Partial credit: no Markdown error body was detected.
How to pass
Keep the correct HTTP 404 status. The remaining requirement is a Markdown error body when agents request Accept: text/markdown. Include at least 20 characters explaining the error and a link to your docs, sitemap, or llms.txt. Verify with curl -sS -L -i -H 'Accept: text/markdown' https://yourdomain.com/some-path-that-does-not-exist. Check both the final 404 status and the Markdown body with Content-Type: text/markdown. Checking the status alone does not verify the missing requirement.
Valid sitemap found at https://graphify.com/sitemap.xml with 123 entries
Rich JSON-LD identity: SoftwareApplication with name, description, url, and category/offers (1 block)
Pricing page found at /pricing
Documentation site found at https://docs.graphify.com
All metadata signals present: canonical URL, lang="en", og:image, og:type
Organization schema found but missing: contactPoint, address
How to pass
Add Organization JSON-LD that includes both contactPoint (with email/phone and contactType) and address (PostalAddress). This lets AI verify your business legitimacy and answer contact queries.
All trust anchor pages verified: About, Contact, Privacy
All 6 measured pages fit an agent context budget (largest ~2K tokens)
REST API documentation found at https://docs.graphify.com/platform/verification. Best-of-protocols score: 7/7.
Onboarding signals described but not verified live: free tier available, self-serve key generation, sandbox/test environment
How to pass
Offer a free tier or trial, self-serve API key generation, and a sandbox environment. Agents can't fill out 'contact sales' forms.
MCP server connected via Streamable HTTP - Graphify v1.0.0 (protocol 2025-11-25)
No REST rate-limit headers found on probed endpoints
How to pass
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
OpenAPI defines a typed error schema in components.schemas and 4xx/5xx responses reference it
API versioning found (URL versioning (servers or paths)) but no deprecation or sunset policy detected - add Sunset/Deprecation headers or a deprecation policy page
How to pass
Declare a versioning policy agents can rely on: version your API (in the URL path or a version header) and publish how you signal deprecation (a Sunset/Deprecation header or a documented timeline). Agents avoid integrating against a surface that can change without warning.
CLI tool found on PyPI: graphify-cli
90% of operations define typed response schemas, 89% use application/json
REST: agent-friendly schema (185 operations, 100% with operationIds, 100% documented by description or summary)
Compatible: 185/185 ops with IDs, 159/185 with typed schemas
1/1 resources read with valid mimeType and non-empty content
Name search surfaced no pages on graphify.com, although developer resources exist on the site (API docs, OpenAPI spec, developer portal, auth docs, MCP server) - weak search indexing or transient search noise
How to pass
Check whether your developer resources (API docs, OpenAPI spec, auth docs, developer portal, MCP server, SDK documentation) surface in name-based searches. If they do not, use predictable URLs, link them in llms.txt, and include your product name in page titles and headings. This result reflects one search sample.
Agent config found: github.com/graphify-labs/graphify/blob/master/AGENTS.md
1 official skill published on skills.sh - 8,337 total installs (skills.sh/graphify-labs)
pricing.md found at /pricing.md but thin (7 lines) - add plan tiers, prices, and feature breakdowns
How to pass
Create a /pricing.md file with your pricing tiers, features, and limits in plain markdown. This lets AI agents compare costs and recommend plans without scraping HTML pricing pages.
MCP server referenced in llms.txt
Found the llms.txt at https://graphify.com/llms.txt.
The llms.txt is well-formatted: 100 lines with markdown links, 20,843 characters in total.
When-to-use guidance found in llms.txt
Skills.sh presence exists but limited - 1 skill (goal: 5+)
How to pass
Expand your skills.sh presence with multiple skill repos covering different use cases. Add descriptive skill names, clear SKILL.md files, and organize by capability area.
Strong entity linking via sameAs: github.com, linkedin.com
All 5 probed llms.txt links resolve to real content
Code fences balanced across 1 markdown document
Developer portal found at /docs
Returns markdown when requested via Accept header
All 3 tools on docs MCP have detailed descriptions (>= 30 chars)
3/3 tools on docs MCP have parameter schemas
docs MCP identifies as "Graphify" v1.0.0 with instructions
docs MCP exposes 3 tool(s) - focused docs surface
All 3 tool names follow consistent convention, descriptive, and non-generic
docs MCP is public - correct posture for documentation surface
RFC 9728 metadata at https://api.graphify.com: resource=https://api.graphify.com, authorization_servers (1), scopes_supported (1), bearer_methods_supported
Only PRM present; spec calls for both PRM and AS metadata
How to pass
Publish RFC 9728 protected-resource metadata at /.well-known/oauth-protected-resource on your resource server (the host that actually serves the API, e.g. api.) with resource and authorization_servers. Publish RFC 8414 authorization-server metadata at /.well-known/oauth-authorization-server on the AS origin, and include the WorkOS auth.md agent_auth block with identity_endpoint, identity_types_supported drawn from the spec enum (anonymous, identity_assertion, service_auth - the assertion variant, the ID-JAG URN urn:ietf:params:oauth:token-type:id-jag, belongs inside identity_assertion.assertion_types_supported, not at the top level), and the identity_assertion.assertion_types_supported block when you advertise that type, so agents can check their assertion shape is accepted before minting. Cross-link by listing the AS origin in PRM authorization_servers, and point agent_auth.skill back at your published /auth.md. Spec: https://github.com/workos/auth.md.
docs MCP returns structured JSON-RPC errors with code and message
docs MCP uses modern Streamable HTTP transport
WebMCP mentioned in documentation at /docs but not implemented on homepage
How to pass
Expose in-page tools through WebMCP, a proposed web standard for browser agents. Register tools with document.modelContext.registerTool() and use navigator.modelContext only as a trailing compatibility fallback. Declarative forms with toolname and tooldescription provide server-rendered evidence, but remain a preview and should not be your only tool surface. Chrome's origin trial covers versions 149-156, with shipping currently targeted for 157. ChatGPT can discover and call WebMCP site tools in the desktop app's built-in browser when the feature is available.
Cursor-based pagination found in OpenAPI spec response schemas or query parameters
202 Accepted responses found alongside a job-style path (/jobs, /operations, /tasks, /async, or {id}/status) but the 202 itself carries no Location header or job-tracking fields
How to pass
For long-running operations, return 202 Accepted and point agents at where to poll for the result (a status/location reference plus a job identifier in the body), documented in your OpenAPI spec, so work that does not finish in one request is still followable.
docs MCP: 3/3 tools have behavioral annotations
MCP server card found at https://docs.graphify.com/.well-known/mcp/server-card.json (2 tools advertised)
Batch endpoint found in OpenAPI spec (/batch path)
Server HTML is a well-structured document (main=true, landmarks=4/4, h1=1, maxHeadingSkip=1).
99 native controls, 0 non-native div-soup affordances (100% native).
99/99 interactive elements have a computable accessible name (100%).
1/1 form controls have an associated label (100%).
No hidden instruction text detected in accessibility-tree attributes or off-screen content.
What does graphify.com do and who is it for? Explain it back to me.
Sign me up for Vercel product updates and marketing emails.
Unsubscribe anytime. Privacy Notice
Source: Ora API
What does graphify.com do and who is it for? Explain it back to me.
11 steps5 reasoning steps
The agent successfully assembled a coherent explanation of Graphify's core purpose, target users, pricing structure, and differentiation by combining the homepage, pricing page, and docs. The site publishes sufficient information for evaluation, though exact pricing numbers and feature tier details remain unexposed.