supabase.com
Ready with a few material gaps
Technical readiness score
The agent completed the observed task
One run shows how an agent performed, but it does not determine the technical score.
Task
What does supabase.com do and who is it for? Explain it back to me.
19 steps7 reasoning steps4 searches
Critical access needs attention
These checks describe whether an ordinary agent can enter, read, and operate the public site.
- 3 / 3 passed
Agents can reach the site
Crawler access, bot defenses, and explicit agent policy.
- 1 / 2 passed
Core content is available
Useful content remains accessible without a fragile browser-only path.
- 1 / 2 passed
Navigation fails safely
Redirects and missing pages give agents a recoverable path.
- 3 / 3 passed
Controls are understandable
Forms and interactive controls expose usable names and structure.
Advertised capabilities have material gaps
Optional surfaces appear only when the scan finds positive evidence that the site offers them.
Public website
Needs work
10 of 19 mature checks passed
API
Needs work
5 of 9 mature checks passed
Authentication
Strong
2 of 3 mature checks passed
MCP
Ready with gaps
0 of 1 mature checks passed
Fix these gaps first
Critical access gaps come first, followed by gaps in capabilities the site advertises.
- 01Critical access
Content without JavaScript
Server-side render your homepage so AI crawlers see meaningful content without JavaScript. Ensure an H1 and 500+ chars of text in raw HTML.
- 02Critical access
Agent-friendly 404s
Return a real HTTP 404 (or 410) status for nonexistent paths - never a 200 with your app shell, which makes agents believe every path exists. For full credit, give the 404 response a short markdown body pointing agents at your sitemap, llms.txt, or docs index. Verify with `curl -s -o /dev/null -w "%{http_code}" https://yourdomain.com/some-path-that-does-not-exist` - it must print 404.
- 03Advertised capabilities
OpenAPI spec published
Publish an OpenAPI (Swagger) specification at /openapi.json or /api/openapi.yaml. This is how agents understand your API surface automatically.
- 04Advertised capabilities
OAuth 2.0 support
Implement OAuth 2.0 for API authentication. Publish your authorization server metadata at /.well-known/oauth-authorization-server.
- 05Advertised capabilities
JSON-LD structured data
Add JSON-LD structured data to your homepage (Organization, Product, or SoftwareApplication schema) so AI can parse your identity programmatically.
Audit the checks behind the score
Applicable evidence is grouped by how it contributes to this preview model. Bonus checks appear only when they add points.
Essential7 of 11 passed · 61.3 / 80 points
- Content without JavaScriptPartial (33%)
- Not blocked by bot detectionPassed
- robots.txt agent-user policyPassed
- Redirect hygienePassed
- Content behind authPassed
- OpenAPI spec publishedFailed
- Agent crawler reachabilityPassed
- OAuth 2.0 supportPartial (60%)
- Scoped permissionsPassed
- JSON error responsesPassed
- Agent-friendly 404sPartial (50%)
Recommended10 of 21 passed · 13.2 / 20 points
- Developer resource discoverabilityPartial (67%)
- Brand name discoverabilityPassed
- robots.txt AI crawler policyPartial (50%)
- Sitemap existsPassed
- Content efficiencyFailed
- JSON-LD structured dataFailed
- Public API/docs linked from homepagePassed
- Agent instruction / when-to-usePartial (67%)
- Metadata completenessPartial (50%)
- Organization schema completenessFailed
- Trust anchor pagesPassed
- Page token budgetPassed
- Code fence validityPassed
- Developer portalPassed
- Public API with reachable endpointsPassed
- Agent onboarding frictionPassed
- MCP server / manifestPartial (83%)
- CLI tool availablePassed
- Multi-language SDK packagesPartial (67%)
- API schema complexity analysisFailed
- Function calling compatibilityFailed
Bonus signals26 positive · +5 points
- Listed in MCP registriesPassed
- NPM/PyPI SDK packagePassed
- Listed on skills.shPassed
- ChatGPT app listedPassed
- Agent discovery filePassed
- Agent Skills index conformance (v0.2.0)Partial (50%)
- pricing.md existsPassed
- MCP well-known discoveryPartial (50%)
- HTTP Link headers (RFC 8288)Passed
- llms.txt existsPassed
- llms.txt formattingPassed
- Skills.sh skill qualityPassed
- llms.txt links resolvePassed
- Markdown alternate linkPassed
- API catalog (RFC 9727)Partial (50%)
- Markdown agent docsPassed
- Markdown content negotiation (acceptmarkdown.com)Passed
- MCP auth mechanismPassed
- MCP OAuth metadataPassed
- MCP PKCE S256 supportPassed
- auth.md existsPassed
- Agent auth WWW-Authenticate hintPassed
- Accessible document structurePassed
- Native interactive controlsPassed
- Accessible names on controlsPassed
- Accessibility-tree injection safety (bonus)Passed
Inspect the underlying audit
The complete Ora audit uses evidence from the scan on . After applying changes, run another scan from the homepage to refresh these recommendations.
Score alerts
A weekly report with ranking changes, new agent feedback, and score alerts for supabase.com.
Source: Ora API
Snapshot 2026-08-15T13-11-49-975+00-00