workos.com/docs
Finalizing the report
Preparing the stored Is Agentic score
workos.com/docs
Preparing the stored Is Agentic score
workos.com/docs
These checks describe whether an ordinary agent can enter, read, and operate the public site.
Agents can reach the site
Crawler access and bot defenses.
Core content is available
Useful content remains accessible without a fragile browser-only path.
Navigation fails safely
Redirects and missing pages give agents a recoverable path.
Controls are understandable
Forms and interactive controls expose usable names and structure.
The public website is always evaluated. Optional surfaces appear when the scan finds positive evidence that they apply.
Strong
Weighted across 16 applicable checks
Strong
Weighted across 12 applicable checks
Ready with gaps
Weighted across 3 applicable checks
Ready with gaps
Weighted across 1 applicable check
Critical access gaps come first, followed by other applicable readiness gaps.
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
Make your API spec self-describing: a unique operationId and a description on every operation, typed parameters, and response schemas. For GraphQL, a fully typed schema with a documented cost or rate limit reads best.
Declare a versioning policy agents can rely on: version your API (in the URL path or a version header) and publish how you signal deprecation (a Sunset/Deprecation header or a documented timeline). Agents avoid integrating against a surface that can change without warning.
Add description, url, and one of sameAs / jobTitle / worksFor to the Person JSON-LD entity for full score.
Checks are grouped by relevance for App sites.
8772 chars, semantic headings (1 H1 + 6 H2s + 5 H3s), 10.0% content ratio
Site accessible to 6 AI agent user-agents
No meta-refresh stubs, JavaScript-redirect stubs, or cross-domain hops across 6 checked pages
All 5 sampled pages are publicly readable (5 with substantive content)
OpenAPI spec found at https://workos.com/openapi.json (version: 3.1.1)
Canonical URL serves text/markdown and text/html via Accept negotiation with Vary: Accept
All major AI crawlers can reach the site: ChatGPT-User, ClaudeBot, Google-Extended, ora-agent, DeepSeekBot.
OAuth authorization server metadata at https://signin.workos.com
OpenAPI declares security schemes but no named OAuth scopes - agents get all-or-nothing access. Declare per-scope grants (e.g. read:*, write:*) in the spec.
How to pass
Declare scoped API permissions where machines can read them: named OAuth scopes in your OpenAPI security schemes, or scopes_supported in RFC 9728 protected-resource metadata. Prose descriptions of roles help humans, but agents need the machine-readable declaration to request least-privilege access.
API returns JSON error responses (404 at https://api.workos.com (from OpenAPI servers))
Nonexistent paths return HTTP 404 with markdown guidance for agents - the strongest 404 contract
Agent discovered 2 developer-resource types by name (OpenAPI spec, auth docs) across 7 pages
workos.com appears at position #2 in a clean brand-name search for "WorkOS identity auth" (8 total matches)
Valid sitemap found at https://workos.com/sitemap.xml with multiple sitemaps entries
JSON-LD Person found - missing description, url, and one of sameAs / jobTitle / worksFor on this entity
How to pass
Add description, url, and one of sameAs / jobTitle / worksFor to the Person JSON-LD entity for full score.
Pricing page found at /pricing
Documentation site found at https://workos.com
When-to-use guidance found in llms.txt
All metadata signals present: canonical URL, lang="en", og:image, og:type
All trust anchor pages verified: About, Contact, Privacy
All 7 measured pages fit an agent context budget (largest ~4K tokens)
Code fences balanced across 1 markdown document
Developer portal found at /docs
Documented REST API detected; endpoints require authentication (API key / OAuth), which is expected for agent access. GraphQL endpoint at https://api.workos.com/graphql is reachable; introspection requires authentication (API key / OAuth), which is expected for agent access. Best-of-protocols score: 7/7.
Low friction onboarding verified live: free tier available, self-serve key generation, sandbox/test environment, zero-auth access, zero-friction self-serve registration at /register
MCP server detected at https://mcp.workos.com/mcp; it requires authentication. Presence is verified (5/6), but Ora could not inspect its tools or verify access scopes without credentials.
How to pass
Keep authentication enabled. Verify tool listing with an authorized MCP client. This unauthenticated scan cannot establish whether protected tools are missing or unusable.
No REST rate-limit headers found on probed endpoints (GraphQL signal: fail 0).
How to pass
Return standard rate-limit headers on your API responses (the RFC RateLimit headers, plus Retry-After on a 429) so agents can self-throttle in real time, and document the conventions alongside your API.
OpenAPI defines a typed error schema in components.schemas and 4xx/5xx responses reference it
API versioning found (URL versioning (servers or paths)) but no deprecation or sunset policy detected - add Sunset/Deprecation headers or a deprecation policy page
How to pass
Declare a versioning policy agents can rely on: version your API (in the URL path or a version header) and publish how you signal deprecation (a Sunset/Deprecation header or a documented timeline). Agents avoid integrating against a surface that can change without warning.
CLI tool found on PyPI: workos
83% of operations define typed response schemas, 83% use application/json
REST: agent-friendly schema (263 operations, 100% with operationIds, 100% documented by description or summary) | GraphQL: introspection auth-gated and no schema evidence in docs | Combined score: 1/2
How to pass
Make your API spec self-describing: a unique operationId and a description on every operation, typed parameters, and response schemas. For GraphQL, a fully typed schema with a documented cost or rate limit reads best.
Compatible: 263/263 ops with IDs, 263/263 with typed schemas
NPM package found: workos - "The Official Workos CLI"
Agent config found: github.com/workos/cli/blob/main/CLAUDE.md
MCP manifest has name and description but no icon at /.well-known/mcp.json
How to pass
Give your MCP server-card (at /.well-known/mcp/server-card.json) a display name, an icon or logo, and a description - all three together are what reads as a complete, branded listing agents can present.
Found in ChatGPT app directory: "WorkOS"
1 official skill published on skills.sh - 2,680 total installs (skills.sh/workos)
Structured pricing.md found at /pricing.md (67 lines)
MCP server discoverable at standard path https://workos.com/.well-known/mcp.json
Modular llms.txt files found for sections: docs, reference
100% of 500 sampled sitemap entries carry lastmod; newest is 0 day(s) old
Found the llms.txt at https://workos.com/llms.txt.
The llms.txt is well-formatted with markdown links, but at 97,682 characters it exceeds the 30,000-character recommendation for a navigation index.
How to pass
Format your llms.txt as a navigation index: start with a markdown heading, include markdown links to deeper resources, and keep it under 30,000 characters. If you have more to say, move long-form content into /llms-full.txt or per-section files (e.g. /docs/llms.txt, /api/llms.txt) and link to them from the main index.
Skills.sh presence exists but limited - 1 skill (goal: 5+)
How to pass
Expand your skills.sh presence with multiple skill repos covering different use cases. Add descriptive skill names, clear SKILL.md files, and organize by capability area.
Strong entity linking via sameAs: linkedin.com, github.com
All 5 probed llms.txt links resolve to real content
Path-suffix markdown docs served with text/markdown content-type: /auth.md
product MCP requires authentication with OAuth metadata discovery
RFC 8414 OAuth metadata for product MCP: issuer=https://signin.workos.com, auth and token endpoints present; client registration: CIMD (client_id_metadata_document_supported)
OAuth metadata for product MCP supports PKCE S256 code challenge
RFC 9728 metadata at https://mcp.workos.com: resource=https://mcp.workos.com/mcp, authorization_servers (1), bearer_methods_supported
auth.md at https://workos.com/auth.md served as text/markdown; charset=utf-8 (5000 chars)
auth.md at https://workos.com/auth.md - 3/8 walkthrough sections (found Register, Claim, and Use credential; missing Discover, Pick a method, Exchange, Errors, and Revocation); anchors: claim_token
How to pass
Structure /auth.md as the WorkOS spec prescribes: sections for Discover, Pick a method, Register, Claim, Exchange, Use the access_token, Errors, and Revocation, with spec anchor keywords (agent_auth, identity_endpoint, identity_assertion, service_auth, id-jag, WWW-Authenticate). Reference https://github.com/workos/auth.md.
Static fallback (deep check disabled): PRM + AS metadata both reachable with agent_auth.identity_endpoint (https://signin.workos.com/agent/identity); walkthrough discoverable end-to-end
PRM + AS metadata cross-linked (PRM discovered at https://mcp.workos.com) (AS metadata fetched from advertised origin https://signin.workos.com) with agent_auth.identity_endpoint (https://signin.workos.com/agent/identity) and identity_types_supported [service_auth] but agent_auth.skill (https://signin.workos.com/agent/auth.md) does not match the published /auth.md (https://workos.com/auth.md)
How to pass
Publish RFC 9728 protected-resource metadata at /.well-known/oauth-protected-resource on your resource server (the host that actually serves the API, e.g. api.) with resource and authorization_servers. Publish RFC 8414 authorization-server metadata at /.well-known/oauth-authorization-server on the AS origin, and include the WorkOS auth.md agent_auth block with identity_endpoint, identity_types_supported drawn from the spec enum (anonymous, identity_assertion, service_auth - the assertion variant, the ID-JAG URN urn:ietf:params:oauth:token-type:id-jag, belongs inside identity_assertion.assertion_types_supported, not at the top level), and the identity_assertion.assertion_types_supported block when you advertise that type, so agents can check their assertion shape is accepted before minting. Cross-link by listing the AS origin in PRM authorization_servers, and point agent_auth.skill back at your published /auth.md. Spec: https://github.com/workos/auth.md.
agent_auth endpoints reachable (source: AS metadata agent_auth block) - identity_endpoint: HTTP 405, claim_endpoint: HTTP 405, events_endpoint: not advertised
REST Idempotency-Key header found on POST /audit_logs/events in OpenAPI spec (GraphQL signal: fail 0).
Cursor-based pagination found in OpenAPI spec response schemas or query parameters
202 Accepted responses found but no clear polling pattern (Location header, /jobs path, or job_id schema)
How to pass
For long-running operations, return 202 Accepted and point agents at where to poll for the result (a status/location reference plus a job identifier in the body), documented in your OpenAPI spec, so work that does not finish in one request is still followable.
SDK packages found across 4 ecosystems: npm, pypi, go, rubygems
Server HTML is a well-structured document (main=true, landmarks=4/4, h1=1, maxHeadingSkip=1).
131 native controls, 0 non-native div-soup affordances (100% native).
130/131 interactive elements have a computable accessible name (99%).
No hidden instruction text detected in accessibility-tree attributes or off-screen content.
What does workos.com do and who is it for? Explain it back to me.
Sign me up for Vercel product updates and marketing emails.
Unsubscribe anytime. Privacy Notice
Source: Ora API
What does workos.com do and who is it for? Explain it back to me.
17 steps6 reasoning steps1 search
The agent satisfied the task by assembling a comprehensive explanation of WorkOS from a mix of site-published machine-readable resources and prior knowledge. The site publishes an LLM-friendly index (llms.txt) and markdown pricing document (pricing.md) that directly answered the core questions; the agent supplemented these with HTML feature pages and external search results to fill gaps around competitive positioning. The site's agent-readiness was moderate—key information was published in structured, fetchable formats, but product organization was scattered and no formal competitor comparisons existed on-site.