# Cal.com: 33 point Door Gap
- Site: cal.com
- Scanned: 2026-09-09
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/cal-da6r27
- Scanner version: 27
1 human and 5 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 80/100 (1/4 dimensions) |
| Agents | 47/100 (5/6 dimensions) |
| Composite | 64/100 |
| Door Gap | 33 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 9 of 14 checks, but could not find a published agent interface. It came up empty on 4 other checks too. 1 checks could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- ok      find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- ok      read the developer documentation
- missing read the prices without running JavaScript
- ok      find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## What a visitor meets
1. **Entry observation** (observed). Primary entry is "Get started". 2 steps from the homepage. no typed fields, sign in with a provider only. 2 sign in options: google, microsoft.
## Top issues
1. **The checked comparison response contained limited text in its initial HTML.** (machine_discoverability)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/cal-da6r27
## Files generated from this scan
- **Prices in the HTML, not only after JavaScript** at `pricing page`, 1 hour, developer. Verify: The next scan reads the prices in the raw HTML of the pricing page, with none needing JavaScript to appear.
- **A comparison page brief** at `/compare/cal-com-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/cal-da6r27
## The agent door
- **machine_discoverability** 64/100. No restriction on the tested crawler names was found in robots.txt. on its first visit, our browser read the homepage. no user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** not measured. Not measured: robots.txt did not permit our scanner to read the required page.
- **pricing_legibility** 30/100. 4 prices appear only after JavaScript runs. a client that does not render pages sees no price at all.
- **agent_aware_instrumentation** 30/100. No MCP manifest was identified at the discovery paths checked. OAuth authorization-server metadata is published; this alone does not identify an MCP endpoint. developer documentation describes an API, but only in prose.
- **machine_fetchable_trust** 85/100. Security.txt is published with a contact route. the homepage answers automated requests.
- **commercial_rails** 25/100. The pricing page includes a sales route and no prices were identified in its raw HTML. a self-serve signup entry was observed from the homepage.
## The human door
- **steps_to_first_value** 80/100. A signup page with provider options was reached in 2 steps from the homepage.
- **required_fields** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
