{"slug":"boka-ygydar","companyName":"Boka","domain":"boka.com","url":"https://boka.com","headline":"A browser-blocking storefront that welcomes AI crawlers in robots.txt but refuses them at the network edge, breaking assistant shopping while publishing the data agents need.","compositeScore":74,"humanScore":81,"agentScore":67,"doorGap":14,"humanMeasured":4,"agentMeasured":6,"percentile":null,"humanPercentile":null,"agentPercentile":null,"isPartial":false,"depth":"free","siteClass":"ecommerce","scannerVersion":12,"scannedAt":"2026-09-08T14:41:14.548Z","unlocked":false,"mission":{"steps":[{"url":"https://www.boka.com","outcome":"ok","purpose":"reach the site at all"},{"url":"https://www.boka.com/robots.txt","outcome":"ok","purpose":"find out whether machines are welcome"},{"url":"https://www.boka.com","outcome":"missing","purpose":"ask whether the door opens for requests carrying the AI crawlers' names"},{"url":"https://www.boka.com/llms.txt","outcome":"ok","purpose":"read the site's own guide for language models"},{"url":"https://www.boka.com/sitemap.xml","outcome":"ok","purpose":"find out what pages exist"},{"url":"https://www.boka.com/.well-known/security.txt","outcome":"missing","purpose":"find a contact route for machines"},{"url":"https://www.boka.com","outcome":"missing","purpose":"find a published agent interface"},{"url":"https://www.boka.com/.well-known/ai-plugin.json","outcome":"missing","purpose":"find an agent plugin manifest"},{"url":"https://www.boka.com","outcome":"missing","purpose":"find out whether verified agents are recognised"},{"url":"https://www.boka.com","outcome":"ok","purpose":"read the homepage as data rather than as a page"},{"url":"https://www.boka.com","outcome":"missing","purpose":"find a machine readable API spec"},{"url":"https://www.boka.com","outcome":"missing","purpose":"read the developer documentation"},{"url":"https://www.boka.com","outcome":"ok","purpose":"read the prices without running JavaScript"},{"url":"https://www.boka.com","outcome":"ok","purpose":"read the product catalogue as data"},{"url":"https://www.boka.com","outcome":"ok","purpose":"read a product page as data"},{"url":"https://www.boka.com","outcome":"ok","purpose":"read the returns and shipping terms"},{"url":"https://www.boka.com","outcome":"ok","purpose":"walk the way a visitor would, to a signup form or a product"}],"verdict":"The agent got through 10 of 17 requests, but could not ask whether the door opens for requests carrying the AI crawlers' names. It came up empty on 6 other checks too."},"observations":null,"dimensions":[{"key":"machine_discoverability","audience":"agent","score":68,"summary":"The site publishes a sitemap listing 54 URLs including product pages, declares llms.txt, and serves 10 schema.org types on the homepage. A real browser is refused entirely, which is how assistant shopping arrives, and the network edge.","evidence":{"locked":true,"count":4}},{"key":"programmatic_onboarding","audience":"agent","score":10,"summary":"No API documentation is linked from the homepage or discoverable in the raw HTML. No OpenAPI spec exists at any of the 6 standard paths. The site publishes a UCP manifest for transactional capability but offers no developer surface to.","evidence":{"locked":true,"count":3}},{"key":"pricing_legibility","audience":"agent","score":90,"summary":"Prices appear in the raw HTML of all 3 product pages checked, with 9 prices on the homepage itself. Product structured data publishes price and currency on every offer. The visible price ($11.62) matches the structured data.","evidence":{"locked":true,"count":2}},{"key":"agent_aware_instrumentation","audience":"agent","score":57,"summary":"A Universal Commerce Protocol manifest is published with 8 capabilities and 3 payment handlers, and a storefront MCP endpoint answers agent calls. The catalogue answers as data at /products.json with brand on each product.","evidence":{"locked":true,"count":4}},{"key":"machine_fetchable_trust","audience":"agent","score":77,"summary":"The returns policy and shipping policy both read as text at their published URLs. Return policy is also in structured data. Shipping terms are in structured data. The homepage answers automated requests. No security.txt is published.","evidence":{"locked":true,"count":3}},{"key":"commercial_rails","audience":"agent","score":100,"summary":"Product markup carries price, currency, identifier and brand. The catalogue answers as data at /products.json, ready for feed syndication. Return policy is in structured data and reads as text. Shipping policy reads as text.","evidence":{"locked":true,"count":4}},{"key":"steps_to_first_value","audience":"human","score":95,"summary":"A product with its price ($11.62) and an add-to-cart control is reachable in 2 steps from the homepage. The price is visible on the page. No account is required to proceed.","evidence":{"locked":true,"count":1}},{"key":"required_fields","audience":"human","score":80,"summary":"The product page does not demand an account before buying. Four express wallets (Apple Pay, Shop Pay, PayPal, Google Pay) skip the form entirely. The page carries 8 input fields with 1 constraint and 5 live regions for validation feedback.","evidence":{"locked":true,"count":1}},{"key":"verification_walls","audience":"human","score":75,"summary":"No sign-in requirement appears on the product page. The site does not force account creation before checkout. Express payment options bypass form entry.","evidence":{"locked":true,"count":1}},{"key":"error_recovery","audience":"human","score":75,"summary":"Three size or colour choosers on the product page let a shopper correct a selection before adding to cart. The page includes 1 inline error container and 5 live regions for validation feedback.","evidence":{"locked":true,"count":1}}],"issues":[{"rank":1,"title":"A real browser cannot load the homepage, blocking all assistant shopping that runs inside a browser.","dimensionKey":"machine_discoverability","evidence":{"locked":true,"count":3},"fix":null},{"rank":2,"title":"No OpenAPI specification was found at the 6 standard paths checked, so a client must be written from prose instead of generated.","dimensionKey":"programmatic_onboarding","evidence":{"locked":true,"count":2},"fix":null},{"rank":3,"title":"No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.","dimensionKey":"programmatic_onboarding","evidence":{"locked":true,"count":1},"fix":null}],"fixArtifacts":{"locked":true,"count":7,"summaries":[{"id":"bot_wall_guidance:notes","kind":"bot_wall_guidance","title":"Let verified assistants through","path":"notes","effort":{"minutes":60,"role":"developer"},"outcome":{"dimension":"machine_discoverability","external":["Assistant shopping and search crawlers reach the product, pricing and policy pages a buyer asks about."]}},{"id":"product_jsonld_liquid:snippets-seconddoor-product-jsonld-liquid","kind":"product_jsonld_liquid","title":"Product markup snippet for every product page","path":"snippets/seconddoor-product-jsonld.liquid","effort":{"minutes":30,"role":"developer"},"outcome":{"dimension":"pricing_legibility","external":["Every Shopify product page carries complete Product markup, not only the sampled ones."]}},{"id":"robots_search_bots:robots-txt","kind":"robots_search_bots","title":"robots.txt rules for AI crawlers","path":"/robots.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["The assistants' search crawlers read and cite the site to buyers; training stays the owner's decision."]}},{"id":"policy_pages_text:notes","kind":"policy_pages_text","title":"Link the policy pages from the product page","path":"notes","effort":{"minutes":30,"role":"owner"},"outcome":{"dimension":"machine_fetchable_trust","external":["Returns and shipping pages read as text and are linked from every product page."]}},{"id":"catalog_identifiers:catalog-identifiers-csv","kind":"catalog_identifiers","title":"Variants missing a GTIN or a brand","path":"catalog-identifiers.csv","effort":{"minutes":5,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["Feed listings stop being rejected for a missing brand or GTIN."]}},{"id":"security_txt:well-known-security-txt","kind":"security_txt","title":"security.txt","path":"/.well-known/security.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_fetchable_trust","external":["Researchers and automated scanners find a disclosure address instead of guessing one."]}},{"id":"interfaces_note:notes","kind":"interfaces_note","title":"Machine interfaces: where you stand","path":"notes","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"agent_aware_instrumentation","external":["The developer surface is built in an order where every published pointer answers."]}}]},"feedback":{"endpoint":"/api/feedback","mcpTool":"rate_fix","targets":[{"type":"report","key":"report"},{"type":"dimension","dimensionKey":"machine_discoverability","key":"dimension:machine_discoverability"},{"type":"dimension","dimensionKey":"programmatic_onboarding","key":"dimension:programmatic_onboarding"},{"type":"dimension","dimensionKey":"pricing_legibility","key":"dimension:pricing_legibility"},{"type":"dimension","dimensionKey":"agent_aware_instrumentation","key":"dimension:agent_aware_instrumentation"},{"type":"dimension","dimensionKey":"machine_fetchable_trust","key":"dimension:machine_fetchable_trust"},{"type":"dimension","dimensionKey":"commercial_rails","key":"dimension:commercial_rails"},{"type":"dimension","dimensionKey":"steps_to_first_value","key":"dimension:steps_to_first_value"},{"type":"dimension","dimensionKey":"required_fields","key":"dimension:required_fields"},{"type":"dimension","dimensionKey":"verification_walls","key":"dimension:verification_walls"},{"type":"dimension","dimensionKey":"error_recovery","key":"dimension:error_recovery"},{"type":"issue","dimensionKey":"machine_discoverability","checkId":"agent_ua_access","key":"issue:machine_discoverability:agent_ua_access"},{"type":"issue","dimensionKey":"programmatic_onboarding","checkId":"openapi","key":"issue:programmatic_onboarding:openapi"},{"type":"issue","dimensionKey":"programmatic_onboarding","checkId":"api_surface","key":"issue:programmatic_onboarding:api_surface"}]}}