# Caraway Home: agent door 50, human door not measured
- Site: carawayhome.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/carawayhome-4w6kwm
- Scanner version: 12
A Shopify storefront with complete product data but no agent checkout protocol or programmatic access for orders.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 50/100 |
| Composite | 50/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 9 of 16 requests, but could not read the site's own guide for language models. It came up empty on 6 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
## Top issues
1. **The catalogue endpoint at /products.json is closed and no product sitemap replaces it, so an assistant has no list of what this store sells.** (machine_discoverability)
2. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
3. **The product feed endpoint is closed, blocking agents from retrieving the catalog programmatically.** (commercial_rails)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/carawayhome-4w6kwm
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Shipping and delivery page** at `/policies/shipping-policy`, 30 minutes, no developer needed. Verify: The next scan reads the shipping policy page as text without JavaScript and finds it linked from a product page.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/carawayhome-4w6kwm
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt or user agent rules. A real browser is served the page normally. The sitemap lists 658 URLs. Five schema.org types are published on the homepage: WebPage, Organization, ImageObject, ContactPoint.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage or published at standard paths. No OpenAPI spec exists at any of the 6 standard paths checked. The site offers no programmatic way for an agent to authenticate, browse products, or place.
- **pricing_legibility** 90/100. Prices are embedded in the raw HTML of all 3 product pages checked, totalling 1734 prices. The homepage itself contains 1035 prices. Product structured data publishes price, currency (USD), and availability without requiring JavaScript.
- **agent_aware_instrumentation** 21/100. No MCP manifest is published at any of the 3 standard paths checked. Shopify as a platform supports agent checkout protocols, but no agent checkout manifest has been published for this store.
- **machine_fetchable_trust** 67/100. No security.txt file is published. The returns policy is readable as plain text at /returns with a 30-day window and free returns. Return policy and shipping terms are published in structured data on product pages.
- **commercial_rails** 10/100. The site runs on Shopify, which supports agent checkout protocols. However, /products.json returns HTTP 404, meaning the default product feed endpoint has been closed. No alternative product feed or agent checkout manifest is published.
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
