Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 16:00 UTC/1 browser pass
A Shopify storefront with agent checkout capability but no API documentation, leaving programmatic buyers without a path to integrate.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail. Not measured is not zero.
Machine discoverability
No AI crawler is blocked by robots.txt or user agent rules; all major AI assistants are explicitly allowed. The site publishes llms.txt, a sitemap with 256 URLs including product pages, and a product feed at /products.json with 12 items.
4 observations recorded.
Programmatic onboarding
No API documentation is linked from the homepage or published at standard paths. No OpenAPI spec exists at any of the 6 standard paths checked. The site offers no developer onboarding surface for programmatic access, only a storefront.
2 observations recorded.
Pricing legibility
Prices are in the raw HTML of the 3 product pages read, 25 prices on the homepage itself, no Product structured data within the first 1.2 MB read of each product page.
2 observations recorded.
Agent-aware instrumentation
A Universal Commerce Protocol manifest is published at version 2026-08-25 with 8 capabilities and 3 payment handlers, declaring a storefront MCP endpoint that agents can call. No MCP manifest exists at the 3 standard paths checked.
4 observations recorded.
Machine-fetchable trust
No security.txt is published at /.well-known/security.txt. The returns policy and shipping policy are readable as text at /policies/refund-policy and /policies/shipping-policy, though neither is embedded in structured data on product.
3 observations recorded.
Commercial rails
The site runs on Shopify and publishes a UCP manifest with payment handlers, enabling agent checkout. However, no API documentation or developer surface exists to guide programmatic integration.
4 observations recorded.
Steps to first value
Could not verify: this scan did not reach the pages that would show it.
Required fields
Could not verify: this scan did not reach the pages that would show it.
Verification walls
Could not verify: this scan did not reach the pages that would show it.
Error recovery
Could not verify: this scan did not reach the pages that would show it.
It got through 9 of 16.
The agent got through 9 of 16 requests, but could not find a contact route for machines. It came up empty on 6 other checks too. That is enough missing for a machine to give up before it reaches a purchase.