PILLAR 01 · DEMAND & VISIBILITY
Part of the Business Growth Architecture. Visibility in search, AI Overviews, ChatGPT and AI agents, built as one integrated source system.
View pillar →
Agentic web audit · Emerging standards 2025/2026 · Last reviewed: September 23, 2026

Can an agent book with you?

As an SEO & GEO expert I offer the agent readiness audit. Can autonomous agents book appointments, configure products, place orders or pay on your website? I check 16 signals in five categories: discoverability, content, bot access control, API/auth/MCP discovery and commerce, covering MCP, WebMCP, x402, ACP, UCP, Web Bot Auth and llms.txt. Delivery: 3 to 4 weeks.

Standards covered
MCP WebMCP x402 ACP Web Bot Auth llms.txt
Murat Ulusoy
Agentic Web
“SEO brings the user. GEO earns the AI citation. Agent readiness lets agents act.”
Murat Ulusoy
CEO · Head of SEO · SUMAX
Signals16
16
Signals checked
5
Categories
3-4 wks
Delivery time
2026
Standards baseline
01 - Definition

What is agent readiness?

Agent readiness is the degree to which a website lets autonomous AI agents act on it, not just read it. Classic SEO makes content indexable for search engines, and generative engine optimization (GEO) makes it citable for large language models. Agent readiness adds the action layer: can an agent book an appointment, place an order, authenticate or pay on a user's behalf? In April 2026 Cloudflare launched its public Agent Readiness score, which tests websites for signals such as robots.txt rules, Markdown for agents, Web Bot Auth, MCP Server Cards, OAuth discovery and agentic commerce standards. The underlying protocols include the Model Context Protocol (MCP), WebMCP, x402, the Agentic Commerce Protocol (ACP) and llms.txt. A site that exposes these signals gives agents structured endpoints, signed identity and callable functions instead of forcing them to parse screenshots and simulate clicks.

Agent-driven purchases, B2B research and service automation all depend on these signals. Early adopters can secure a first-wave advantage, much like the SEO pioneers of the 2000s.

DISCOVERY

Findability

robots.txt, sitemap.xml, HTTP Link headers. Can agents find where your functions are exposed at all?

CONTENT

Machine format

Markdown negotiation, JSON-LD, structured data. Cloudflare measured up to 80 percent fewer tokens than raw HTML in some cases.

TRUST

Bot authentication

Web Bot Auth, Content Signals, AI bot rules (RFC 9309). Access per agent.

ACTION

Action layer

MCP, WebMCP, OAuth discovery, x402, ACP. Structured functions instead of click simulation.

02 - Categories

Five categories, 16 signals.

The audit follows Cloudflare's scoring logic and adds Schema.org coverage, agenticweb.md, .well-known/mcp.json, A2A discovery and LLMFeed. Each signal gets a score (0-3), an effort rating and a prioritized action.

A · DISCOVERABILITY

Findability

  • robots.txt present and maintained
  • sitemap.xml referenced in robots.txt
  • HTTP Link headers (RFC 8288)

The base layer. Without it, agents find no structured way in.

B · CONTENT

Machine format

  • Markdown content negotiation (Accept header)
  • JSON-LD Schema.org coverage
  • llms.txt with a curated overview

Markdown is far cheaper for agents to read than HTML. A typical quick win.

C · BOT ACCESS CONTROL

Trust layer

  • AI bot rules under RFC 9309
  • Content Signals in robots.txt
  • Web Bot Auth request signing

Trusted agents get in, unverified ones are throttled.

D · API / AUTH / MCP / SKILLS

Action layer

  • API Catalog (RFC 9727)
  • OAuth/OIDC discovery (RFC 8414, 9728)
  • MCP Server Card (SEP-1649)
  • Agent Skills index
  • WebMCP endpoints (browser-native)

Here your site becomes transactional: agents call typed functions instead of scraping.

E · COMMERCE

Payment layer

  • x402 payment protocol (HTTP 402)
  • UCP profile (Universal Commerce)
  • ACP discovery document

Stablecoin micropayments and agent checkouts. Optional, but strategic.

+ EXTENDED

Supplementary signals

  • .well-known/mcp.json (LLMFeed)
  • agenticweb.md discovery
  • A2A agent-to-agent endpoints
  • NLWeb Schema.org integration

Not yet in the Cloudflare score, but in my assessment likely to gain adoption in 2026/2027.

03 - Standards

The key protocols in detail.

I check not only whether a standard is present, but also implementation quality, version status and fit for your industry. The central standards of 2026:

ANTHROPIC · 2024

Model Context Protocol (MCP)

Open JSON-RPC protocol for tool discovery and tool calls, the de facto standard for agent-tool integration. Adobe Commerce, Shopify and major SaaS platforms offer MCP servers.

W3C / CHROME · 2026

WebMCP

Browser-native variant via navigator.modelContext (Chrome 146+). Early figures attributed to Google cite around 89 percent fewer tokens than screenshot-based automation.

COINBASE · V2 DEC 2025

x402 payment protocol

HTTP-native stablecoin payments via status 402. Stripe supports x402 for USDC on Base since February 2026. Micropayments for pay-per-read and API calls.

OPENAI + STRIPE · 2025

Agentic Commerce Protocol (ACP)

Delegated payments: signed purchase authorizations instead of shared card data. Checkout inside ChatGPT and similar surfaces.

CLOUDFLARE / IETF · 2025

Web Bot Auth

Cryptographic bot verification through signed HTTP requests, a public key directory and an IETF draft. Access rights per agent.

GOOGLE · 2025

A2A & AP2

Agent-to-agent protocol for multi-agent workflows, plus the Agent Payments Protocol as an alternative to ACP. Relevant for procurement flows.

MICROSOFT · 2025

NLWeb

Natural-language queries on top of Schema.org data. A bridge between structured data and conversational agents.

COMMUNITY · 2024

llms.txt

A Markdown file listing your most important URLs. Adoption is still low. A quick win, not a cure-all.

LLMFEED · 2025

.well-known/mcp.json

Static JSON discovery with Ed25519 signatures. Trust verification without running an active MCP server.

04 - Phases

From audit to implementation roadmap.

A documented sequence over three to four weeks, ending in a prioritized backlog.

01

Inventory & baseline (week 1)

Asset review, Cloudflare score run, competitor snapshot, stakeholder mapping, API inventory, schema coverage.

InventoryBaselineStakeholders
02

16-signal audit (weeks 2-3)

All 16 signals plus extended standards. MCP/WebMCP feasibility per function, Web Bot Auth prerequisites, OAuth discovery and commerce protocol fit per product area.

16 signalsMCP feasibilitySchema
03

Roadmap & scoring (weeks 3-4)

Score report, benchmark, investment estimate per action and a 90/180/365-day roadmap with named owners.

RoadmapInvestmentScore
04

Executive briefing (week 4)

Two formats: a technical deep dive for engineering and product, and an executive briefing for CMO and CTO with investment case and competitive risks.

ExecutiveC-levelHandover
● Audit outcome

Clarity on
agent maturity.

Score, roadmap and investment estimate. Backlog items, not theory.

Score coverage16 signals
100%
Quick wins0-30 days
65%
Strategic wins90-365 days
85%
05 - Differentiation

How does agent readiness differ from SEO and GEO?

SEO makes content indexable, GEO makes it citable for language models, and agent readiness makes your functions executable for autonomous agents. It complements SEO and GEO rather than replacing them. A clear line between the three prevents double investment and wrong priorities.

CriterionSEOGEOAgent readiness
GoalIndexing & rankingAI citation & answer inclusionAgent action & transaction
AddresseeSearch engine crawlersLLMs & AI answer systemsAutonomous agents
OutputSERP positionCitation in an AI answerBooking, order, authentication
StandardsHTML, Schema.org, sitemapsSchema graph, passages, WikidataMCP, WebMCP, x402, ACP, OAuth
KPIOrganic trafficCitation rate, AARAgent conversion rate
Maturity in 2026Mature (25+ years)Growing (3 years)Emerging (1-2 years)
06 - Use cases

Where agent readiness pays off first.

Six clusters with the most immediate impact, each with matching protocols, implementation depth and a business KPI.

CLUSTER 01

Agent commerce

Product search, configuration and checkout via ChatGPT, Gemini, Perplexity, Copilot. ACP, x402, UCP, Product schema.

Leverage: high
CLUSTER 02

Service bookings

Availability, slot reservation and confirmations in healthcare, travel, beauty and consulting. MCP for the booking API.

Leverage: high
CLUSTER 03

B2B pipeline automation

Demo requests, pricing configurators, vendor discovery for procurement agents. MCP, OAuth discovery, Schema.org.

Leverage: high
CLUSTER 04

Customer service deflection

Knowledge base access, status queries, self-service without human routing. MCP for support functions.

Leverage: medium
CLUSTER 05

Pay-per-use APIs

Micropayments for data APIs, premium content and compute via x402.

Leverage: emerging
CLUSTER 06

Publishers & editorial

Markdown negotiation, llms.txt, AI bot rules, optionally x402 for premium content. Protection against uncontrolled scraping.

Leverage: medium
07 - Industries

Industries with the most leverage.

Not every industry benefits equally. These six sectors have the greatest potential in 2026, each with its own standards mix.

E-commerce & retail

ACP, UCP, Product schema, stock availability, x402 checkout. Agent shopping in ChatGPT, Gemini and Perplexity as new channels.

Travel & hospitality

MCP for search, availability and booking, ACP for checkout, LodgingBusiness schema, OAuth for loyalty. Booking through conversation.

B2B SaaS

MCP for trial sign-ups, demo booking and docs access. OAuth discovery, API Catalog, pricing schema.

Healthcare

Booking endpoints with YMYL compliance, MedicalEntity schema, Web Bot Auth, OAuth for patient authentication.

Financial services

OAuth discovery, delegated authentication, comparison APIs, Web Bot Auth. Regulatory disclaimers inside MCP tools.

Publishers & media

Markdown negotiation, llms.txt, x402 for paywall access, AI bot rules. Paid access instead of uncontrolled scraping.

08 - Investment

What does an agent readiness audit cost?

It depends on site complexity (URL volume, functional areas, markets), implementation depth and industry. Terms are set in the scope call; every model includes the 16-point score report.

PILOT

Single-brand audit

One brand, one market. 16-signal score plus action plan, ideal as a first reality check.

  • 16-signal score report
  • Comparison with the Cloudflare score
  • 90-day quick-win plan
  • Executive briefing
STANDARD

Multi-brand / multi-market

Up to five brands or markets, plus benchmark and MCP feasibility.

  • Multi-asset 16-signal score
  • Competitor benchmark
  • MCP server feasibility
  • 365-day roadmap
CONTINUOUS

Readiness retainer

Quarterly re-score, monitoring of standard updates (MCP, x402, IETF drafts) and implementation support.

  • Quarterly re-score
  • Standards update monitoring
  • Implementation sparring
  • Roadmap adjustments
09 - Related

Related services.

10 - FAQ

Frequently asked questions.

Common questions about agent readiness, the standards and the audit process.

What is agent readiness and why does it matter in 2026?

Agent readiness measures whether autonomous AI agents can act on your website, not just index or cite it. Since April 2026 Cloudflare's public Agent Readiness score checks discoverability, content, bot access control, API/auth/MCP discovery and, optionally, commerce. Early adopters can gain a first-wave advantage in agent-driven purchase flows.

Which standards does the audit check?

16 signals in five categories: discoverability (robots.txt, sitemap.xml, HTTP Link headers), content (Markdown content negotiation), bot access control (AI bot rules under RFC 9309, Content Signals, Web Bot Auth), API/auth/MCP/skills (API Catalog RFC 9727, OAuth/OIDC discovery, MCP Server Card SEP-1649, Agent Skills index, WebMCP) and commerce (x402, UCP profile, ACP discovery). Plus extended signals: llms.txt, .well-known/mcp.json, A2A and NLWeb.

What is the Model Context Protocol (MCP)?

MCP is an open protocol from Anthropic (2024) that gives agents standardized, JSON-RPC-based access to tools and data. Instead of scraping HTML, an agent calls typed functions such as searchProducts() or bookAppointment(). Adobe released an MCP server for Adobe Commerce in 2026; Shopify and major SaaS platforms offer MCP access too.

What is WebMCP and how does it differ from MCP?

WebMCP is a browser-native variant of MCP (Chrome 146+) built on the navigator.modelContext API. Pages expose tools directly, and agents call typed functions instead of analyzing screenshots. Early figures attributed to Google cite around 89 percent fewer tokens than visual automation. It is still experimental, so the audit assesses feasibility.

What is x402 and what role does it play in agent commerce?

x402 is Coinbase's open protocol for stablecoin payments over HTTP. The server answers with HTTP 402 and payment instructions; the client signs the payment in a request header. Stripe added x402 support for USDC on Base in February 2026. For agent micropayments (pay-per-read, API calls) it is the emerging standard.

What is the Agentic Commerce Protocol (ACP)?

ACP, developed by OpenAI and Stripe, handles secure instant checkouts in AI assistants. Its delegated payment model keeps the card with the merchant; the agent only passes on a signed purchase authorization. For brands it is the lever for being purchasable inside ChatGPT and similar surfaces.

What is Web Bot Auth?

Web Bot Auth is Cloudflare's 2025 mechanism for cryptographic bot identification, now in IETF drafts. A crawler publishes its public key and signs its HTTP requests; the server verifies the identity. Trusted agents get in, unverified ones are throttled.

How does agent readiness differ from SEO and GEO?

SEO makes content indexable, GEO makes it citable for LLMs, and agent readiness makes functions executable for agents. SEO and GEO are about visibility, agent readiness is about action. SEO brings the user, GEO earns the AI citation, agent readiness lets agents transact.

Which use cases does agent readiness enable right away?

Four clusters: agent commerce (search, configuration, checkout via ChatGPT, Gemini or Perplexity), service bookings (healthcare, travel, beauty, consulting), B2B pipeline automation (demo requests, pricing configurators, procurement discovery) and customer service deflection (knowledge base, status queries, self-service).

How long does an audit take and what do I get?

3 to 4 weeks. Phase 1: inventory and Cloudflare baseline. Phase 2: in-depth check of the 16 signals plus extended standards. Phase 3: roadmap, investment estimate, executive briefing. You get a 16-point score report, technical specifications, a briefing deck and a 90/180/365-day backlog.

Which industries benefit most?

Highest leverage: e-commerce (ACP, UCP, x402), travel (MCP booking, ACP), B2B SaaS (MCP for trials and demos), healthcare (booking with YMYL compliance) and financial services (OAuth discovery, delegated authentication). Medium: publishers (llms.txt, Markdown) and local service providers (availability APIs).

What does an agent readiness audit cost?

It depends on site complexity, implementation depth and industry. Three models: pilot (one brand, one market), standard (multi-brand or multi-market with MCP feasibility study) and a continuous retainer (quarterly re-score plus implementation support). Terms are set in the scope call.

Let's talk

Is your site ready for autonomous agents?

A 30-minute scope call: audit model, signals checked, industry specifics and a realistic time and budget frame.

FOR DOCTORS AND CLINICS
Running a practice or clinic? The Profit System turns medical expertise into predictable profit.
See the Profit System →