{"slug":"brooklinen-ym9jjb","companyName":"Brooklinen","domain":"brooklinen.com","url":"https://brooklinen.com","headline":"A Shopify storefront with agent checkout capability but no API documentation, leaving programmatic buyers without a path to integrate.","compositeScore":46,"humanScore":0,"agentScore":46,"doorGap":0,"humanMeasured":0,"agentMeasured":6,"percentile":null,"humanPercentile":null,"agentPercentile":null,"isPartial":true,"depth":"free","siteClass":"unknown","scannerVersion":13,"scannedAt":"2026-09-08T16:00:06.685Z","unlocked":false,"mission":{"steps":[{"url":"https://brooklinen.com","outcome":"ok","purpose":"reach the site at all"},{"url":"https://brooklinen.com/robots.txt","outcome":"ok","purpose":"find out whether machines are welcome"},{"url":"https://brooklinen.com","outcome":"ok","purpose":"ask whether the door opens for requests carrying the AI crawlers' names"},{"url":"https://brooklinen.com/llms.txt","outcome":"ok","purpose":"read the site's own guide for language models"},{"url":"https://www.brooklinen.com/sitemap.xml","outcome":"ok","purpose":"find out what pages exist"},{"url":"https://brooklinen.com/.well-known/security.txt","outcome":"missing","purpose":"find a contact route for machines"},{"url":"https://brooklinen.com","outcome":"missing","purpose":"find a published agent interface"},{"url":"https://brooklinen.com/.well-known/ai-plugin.json","outcome":"missing","purpose":"find an agent plugin manifest"},{"url":"https://brooklinen.com","outcome":"missing","purpose":"find out whether verified agents are recognised"},{"url":"https://brooklinen.com","outcome":"missing","purpose":"read the homepage as data rather than as a page"},{"url":"https://brooklinen.com","outcome":"missing","purpose":"find a machine readable API spec"},{"url":"https://brooklinen.com","outcome":"missing","purpose":"read the developer documentation"},{"url":"https://brooklinen.com","outcome":"ok","purpose":"read the prices without running JavaScript"},{"url":"https://brooklinen.com","outcome":"ok","purpose":"read the product catalogue as data"},{"url":"https://brooklinen.com","outcome":"ok","purpose":"read a product page as data"},{"url":"https://brooklinen.com","outcome":"ok","purpose":"read the returns and shipping terms"}],"verdict":"The agent got through 9 of 16 requests, but could not find a contact route for machines. It came up empty on 6 other checks too. That is enough missing for a machine to give up before it reaches a purchase."},"observations":null,"dimensions":[{"key":"machine_discoverability","audience":"agent","score":99,"summary":"No AI crawler is blocked by robots.txt or user agent rules; all major AI assistants are explicitly allowed. The site publishes llms.txt, a sitemap with 256 URLs including product pages, and a product feed at /products.json with 12 items.","evidence":{"locked":true,"count":4}},{"key":"programmatic_onboarding","audience":"agent","score":10,"summary":"No API documentation is linked from the homepage or published at standard paths. No OpenAPI spec exists at any of the 6 standard paths checked. The site offers no developer onboarding surface for programmatic access, only a storefront.","evidence":{"locked":true,"count":2}},{"key":"pricing_legibility","audience":"agent","score":45,"summary":"Prices are in the raw HTML of the 3 product pages read, 25 prices on the homepage itself, no Product structured data within the first 1.2 MB read of each product page.","evidence":{"locked":true,"count":2}},{"key":"agent_aware_instrumentation","audience":"agent","score":49,"summary":"A Universal Commerce Protocol manifest is published at version 2026-08-25 with 8 capabilities and 3 payment handlers, declaring a storefront MCP endpoint that agents can call. No MCP manifest exists at the 3 standard paths checked.","evidence":{"locked":true,"count":4}},{"key":"machine_fetchable_trust","audience":"agent","score":65,"summary":"No security.txt is published at /.well-known/security.txt. The returns policy and shipping policy are readable as text at /policies/refund-policy and /policies/shipping-policy, though neither is embedded in structured data on product.","evidence":{"locked":true,"count":3}},{"key":"commercial_rails","audience":"agent","score":10,"summary":"The site runs on Shopify and publishes a UCP manifest with payment handlers, enabling agent checkout. However, no API documentation or developer surface exists to guide programmatic integration.","evidence":{"locked":true,"count":4}},{"key":"steps_to_first_value","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"required_fields","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"verification_walls","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}},{"key":"error_recovery","audience":"human","score":null,"summary":"Could not verify: this scan did not reach the pages that would show it.","evidence":{"locked":true,"count":0}}],"issues":[{"rank":1,"title":"No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.","dimensionKey":"programmatic_onboarding","evidence":{"locked":true,"count":1},"fix":null},{"rank":2,"title":"No OpenAPI specification was found at the 6 standard paths checked, so a client must be written from prose instead of generated.","dimensionKey":"programmatic_onboarding","evidence":{"locked":true,"count":2},"fix":null},{"rank":3,"title":"No security.txt or contact information for reporting vulnerabilities is published, leaving security researchers without a clear channel to report issues.","dimensionKey":"machine_fetchable_trust","evidence":{"locked":true,"count":3},"fix":null}],"fixArtifacts":{"locked":true,"count":7,"summaries":[{"id":"robots_search_bots:robots-txt","kind":"robots_search_bots","title":"robots.txt rules for AI crawlers","path":"/robots.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["The assistants' search crawlers read and cite the site to buyers; training stays the owner's decision."]}},{"id":"merchant_policy_jsonld:product-page","kind":"merchant_policy_jsonld","title":"Return policy and shipping structured data","path":"product page","effort":{"minutes":30,"role":"developer"},"outcome":{"dimension":"machine_fetchable_trust","external":["Assistants read the return window and shipping terms from structured data."]}},{"id":"policy_pages_text:notes","kind":"policy_pages_text","title":"Link the policy pages from the product page","path":"notes","effort":{"minutes":30,"role":"owner"},"outcome":{"dimension":"machine_fetchable_trust","external":["Returns and shipping pages read as text and are linked from every product page."]}},{"id":"catalog_identifiers:catalog-identifiers-csv","kind":"catalog_identifiers","title":"Variants missing a GTIN or a brand","path":"catalog-identifiers.csv","effort":{"minutes":5,"role":"owner"},"outcome":{"dimension":"machine_discoverability","external":["Feed listings stop being rejected for a missing brand or GTIN."]}},{"id":"organization_jsonld:homepage","kind":"organization_jsonld","title":"Organization structured data","path":"homepage","effort":{"minutes":15,"role":"developer"},"outcome":{"dimension":"machine_discoverability","external":["Search and assistant crawlers read the company entity from the homepage rather than inferring it."]}},{"id":"interfaces_note:notes","kind":"interfaces_note","title":"Machine interfaces: where you stand","path":"notes","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"agent_aware_instrumentation","external":["The developer surface is built in an order where every published pointer answers."]}},{"id":"security_txt:well-known-security-txt","kind":"security_txt","title":"security.txt","path":"/.well-known/security.txt","effort":{"minutes":10,"role":"owner"},"outcome":{"dimension":"machine_fetchable_trust","external":["Researchers and automated scanners find a disclosure address instead of guessing one."]}}]},"feedback":{"endpoint":"/api/feedback","mcpTool":"rate_fix","targets":[{"type":"report","key":"report"},{"type":"dimension","dimensionKey":"machine_discoverability","key":"dimension:machine_discoverability"},{"type":"dimension","dimensionKey":"programmatic_onboarding","key":"dimension:programmatic_onboarding"},{"type":"dimension","dimensionKey":"pricing_legibility","key":"dimension:pricing_legibility"},{"type":"dimension","dimensionKey":"agent_aware_instrumentation","key":"dimension:agent_aware_instrumentation"},{"type":"dimension","dimensionKey":"machine_fetchable_trust","key":"dimension:machine_fetchable_trust"},{"type":"dimension","dimensionKey":"commercial_rails","key":"dimension:commercial_rails"},{"type":"dimension","dimensionKey":"steps_to_first_value","key":"dimension:steps_to_first_value"},{"type":"dimension","dimensionKey":"required_fields","key":"dimension:required_fields"},{"type":"dimension","dimensionKey":"verification_walls","key":"dimension:verification_walls"},{"type":"dimension","dimensionKey":"error_recovery","key":"dimension:error_recovery"},{"type":"issue","dimensionKey":"programmatic_onboarding","checkId":"api_surface","key":"issue:programmatic_onboarding:api_surface"},{"type":"issue","dimensionKey":"programmatic_onboarding","checkId":"openapi","key":"issue:programmatic_onboarding:openapi"},{"type":"issue","dimensionKey":"machine_fetchable_trust","checkId":"security_txt","key":"issue:machine_fetchable_trust:security_txt"}]}}