Protocol discovery

Explore checks for MCP, A2A, WebMCP, API catalogs and OAuth metadata that help AI agents discover and use your site's services.

Reading a site is one thing; doing something with it is another. These checks look for the well-known documents and headers that tell an agent which APIs, MCP servers, skills, and in-page tools are available, and how to get authorised to use them.

Every check in this category is a bonus check. Passing one adds points to the overall score; lacking one costs nothing, because most sites do not offer an API or tools and should not be marked down for it. Protocol discovery has no category percentage of its own.

Checks in this category

  • MCP Server Card
    A well-known MCP descriptor lets agents discover an available Model Context Protocol server.
  • API Catalog
    RFC 9727 /.well-known/api-catalog lets agents discover available APIs.
  • Rate limit response headers
    RateLimit headers let an agent pace itself instead of discovering your limit by hitting it.
  • OAuth Authorization Server discovery
    RFC 8414 metadata lets agents discover how to obtain authorization.
  • OAuth Protected Resource metadata
    RFC 9728 metadata tells agents which authorization servers protect a resource.
  • Emerging checkAgent Skills
    A skills manifest lists the specific things an agent can call.
  • Emerging checkWebMCP
    WebMCP exposes in-page tools to agents via document.modelContext on the live page.
  • Emerging checkA2A Agent Card
    An Agent-to-Agent card describes your agent’s capabilities and endpoint so other agents can call it.