Skip to content
Boberbot

The 22 checks

What Cloudflare checks for agent readiness, what Boberbot does about each check, and where to read more.

These are the checks of Cloudflare’s isitagentready.com, under Cloudflare’s names. The seven marked Content Site are the ones a marketing site, blog or docs site should pass. Levels: 1 Basic Web Presence, 2 Bot-Aware, 3 Agent-Readable, 4 Agent-Integrated, 5 Agent-Native.

Discoverability

robots.txt

ID robotsTxt, Content Site.

Fix: Serve /robots.txt as text/plain with at least one User-agent group and your allow and disallow rules.

On Astro: Boberbot writes robots.txt at build time.

Cloudflare’s guide, spec

Sitemap

ID sitemap, Content Site.

Fix: Publish an XML sitemap of your canonical URLs and point to it with a Sitemap line in robots.txt.

On Astro: Add @astrojs/sitemap; Boberbot adds the Sitemap line to robots.txt.

Cloudflare’s guide, spec

ID linkHeaders, Content Site.

Fix: Send Link response headers on your pages that point agents to useful resources, for example a Markdown version (rel=“alternate”; type=“text/markdown”) or a description (rel=“describedby”).

Cloudflare’s guide, spec 1, spec 2

DNS-AID

ID dnsAid, Content Site.

Fix: Publish ServiceMode SVCB or HTTPS records under _agents (for example _index._agents.your-domain) and sign the zone with DNSSEC. This lives in DNS, not in your build.

Cloudflare’s guide, spec 1, spec 2

Content accessibility

Markdown negotiation

ID markdownNegotiation, Content Site.

Fix: Answer requests that send Accept: text/markdown with a Markdown version of the page and Content-Type: text/markdown. Browsers keep getting HTML.

Cloudflare’s guide, spec

Bot access control

AI bot rules

ID robotsTxtAiRules, Content Site.

Fix: Give AI crawlers rules in robots.txt: a User-agent: * group, or explicit groups for crawlers such as GPTBot, ClaudeBot, OAI-SearchBot and PerplexityBot.

On Astro: Boberbot’s robots.txt has a wildcard group that applies to every AI crawler.

Cloudflare’s guide, spec 1, spec 2

Content Signals

ID contentSignals, Content Site.

Fix: Add a Content-Signal line to robots.txt, for example: Content-Signal: search=yes, ai-input=yes, ai-train=no

On Astro: Boberbot writes a Content-Signal line (configurable).

Cloudflare’s guide, spec 1, spec 2

Web Bot Auth

ID webBotAuth.

Fix: Only for sites that send bot traffic: publish /.well-known/http-message-signatures-directory with a JWKS.

Cloudflare’s guide, spec

Discovery

MCP Server Card

ID mcpServerCard.

Fix: If you run an MCP server, describe it in /.well-known/mcp/server-card.json (serverInfo with name and version, transport, capabilities).

Cloudflare’s guide, spec

A2A Agent Card

ID a2aAgentCard.

Fix: If you run an A2A agent, publish /.well-known/agent-card.json with name, version and supportedInterfaces.

Cloudflare’s guide, spec

Agent Skills

ID agentSkills.

Fix: Publish /.well-known/agent-skills/index.json listing skills with real content (name, type, description, url, digest).

Cloudflare’s guide, spec

WebMCP

ID webMcp.

Fix: Register tools with document.modelContext.registerTool(), or add toolname and tooldescription attributes to forms.

Cloudflare’s guide, spec

API Catalog

ID apiCatalog.

Fix: If you have APIs, serve /.well-known/api-catalog as application/linkset+json with a linkset entry per API.

Cloudflare’s guide, spec 1, spec 2

OAuth discovery

ID oauthDiscovery.

Fix: If you run OAuth, publish /.well-known/oauth-authorization-server (or openid-configuration) with issuer and endpoints.

Cloudflare’s guide, spec 1, spec 2

OAuth Protected Resource

ID oauthProtectedResource.

Fix: If you protect APIs with OAuth, publish /.well-known/oauth-protected-resource with resource and authorization_servers.

Cloudflare’s guide, spec

Auth.md

ID authMd.

Fix: If agents can register with you, serve /auth.md and publish agent_auth metadata on your authorization server.

Cloudflare’s guide, spec

ARD

ID ard.

Fix: If you have agent resources to list, serve /.well-known/ai-catalog.json with specVersion and entries.

Cloudflare’s guide, spec

Commerce

Shown in every result, never counted: Cloudflare only scores these for shops.

x402

ID x402.

Fix: Commerce only: x402 payment headers on paid API routes.

Cloudflare’s guide, spec

MPP

ID mpp.

Fix: Commerce only: /openapi.json with x-payment-info on payable operations.

Cloudflare’s guide, spec

UCP

ID ucp.

Fix: Commerce only: /.well-known/ucp with protocol version and services.

Cloudflare’s guide, spec

ACP

ID acp.

Fix: Commerce only: /.well-known/acp.json with protocol metadata.

Cloudflare’s guide, spec

AP2

ID ap2.

Fix: Commerce only: declare AP2 in your A2A Agent Card extensions.

spec