workos.com
Technical readiness score
This run is collected separately from the technical score and will appear here as the agent moves through the public site.
These checks describe whether an ordinary agent can enter, read, and operate the public site.
Agents can reach the site
Crawler access, bot defenses, and explicit agent policy.
Core content is available
Useful content remains accessible without a fragile browser-only path.
Navigation fails safely
Redirects and missing pages give agents a recoverable path.
Controls are understandable
Forms and interactive controls expose usable names and structure.
Optional surfaces appear only when the scan finds positive evidence that the site offers them.
Strong
13 of 18 mature checks passed
Needs work
6 of 11 mature checks passed
Strong
2 of 3 mature checks passed
Ready with gaps
0 of 1 mature checks passed
Critical access gaps come first, followed by gaps in capabilities the site advertises.
Server-side render your homepage so AI crawlers see meaningful content without JavaScript. Ensure an H1 and 500+ chars of text in raw HTML.
Return a real HTTP 404 (or 410) status for nonexistent paths - never a 200 with your app shell, which makes agents believe every path exists. For full credit, give the 404 response a short markdown body pointing agents at your sitemap, llms.txt, or docs index. Verify with `curl -s -o /dev/null -w "%{http_code}" https://yourdomain.com/some-path-that-does-not-exist` - it must print 404.
Publish an OpenAPI (Swagger) specification at /openapi.json or /api/openapi.yaml. This is how agents understand your API surface automatically.
Implement OAuth 2.0 for API authentication. Publish your authorization server metadata at /.well-known/oauth-authorization-server.
Support an idempotency key on your write operations and declare it where agents can read it: an Idempotency-Key header parameter on your POST/PUT/PATCH operations in your OpenAPI spec for REST, or a client-supplied id argument on your GraphQL mutations. Agents retry on network failures, and without this a retry can double-charge or duplicate a record.
Applicable evidence is grouped by how it contributes to this preview model. Bonus checks appear only when they add points.
The complete Ora audit uses evidence from the scan on . After applying changes, run another scan from the homepage to refresh these recommendations.
A weekly report with ranking changes, new agent feedback, and score alerts for workos.com.
Source: Ora API
Snapshot 2026-08-19T14-16-58-448Z