# Appcues: agent door 27, human door not measured
- Site: appcues.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/appcues-z74dxr
- Scanner version: 16
Pricing is hidden behind JavaScript and signup cannot be reached from the homepage, blocking both human and agent evaluation.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 27/100 (6/6 dimensions) |
| Composite | 27/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The site refused automated access at www.appcues.com, so the agent could not read the developer documentation.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- blocked read the developer documentation
- ok      read the prices without running JavaScript
- missing find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **docs.appcues.com turn the honest automated client away while serving a real browser, so the search crawlers that would cite the page are turned away by a rule about the client.** (machine_discoverability)
2. **No comparison or alternatives page exists, which is the page an assistant cites when a buyer asks it to shortlist vendors.** (machine_discoverability)
3. **No OpenAPI specification was found at the 6 standard paths checked, so a client must be written from prose instead of generated.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/appcues-z74dxr
## Files generated from this scan
- **A pricing page that states a price** at `/pricing.md`, 1 hour, no developer needed. Verify: The next scan reads at least one price in the raw HTML of the pricing page.
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: The next scan opens the homepage and the key pages in a real browser and under the search crawler names, and every one is served.
- **A comparison page brief** at `/compare/appcues-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/appcues-z74dxr
## The agent door
- **machine_discoverability** 72/100. A real browser is served the site normally and no user agent rule blocks declared AI crawlers. The sitemap lists 517 URLs and llms.txt is published with 173 lines.
- **programmatic_onboarding** 10/100. .
- **pricing_legibility** 20/100. The pricing page says 'starting at' three times but no figure follows any of these phrases. No prices appear in the raw HTML or after rendering. The page does not gate pricing behind a demo or quote request, but the prices themselves are.
- **agent_aware_instrumentation** 8/100. No MCP manifest is published at any of the three standard paths checked. The site does not declare Model Context Protocol support, so agents cannot discover what capabilities are available for integration.
- **machine_fetchable_trust** 40/100. No security.txt file is published at the standard path. The homepage answers automated requests normally, but the absence of a security contact or vulnerability disclosure policy leaves no way for agents or researchers to report issues.
- **commercial_rails** 10/100. .
## The human door
- **steps_to_first_value** not measured. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** not measured. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** not measured. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** not measured. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
