# Hims: agent door 13, human door not measured
- Site: hims.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/hims-prs5fz
- Scanner version: 12
Automated clients are blocked at the HTTP layer, preventing both AI agents and programmatic access to pricing, product information, and signup flows.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 13/100 |
| Composite | 13/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The site refused automated access at hims.com, so the agent could not reach the site at all.
- blocked reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- blocked read the site's own guide for language models
- blocked find out what pages exist
- blocked find a contact route for machines
- blocked find a published agent interface
- blocked find an agent plugin manifest
- blocked find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- blocked find a machine readable API spec
- missing read the developer documentation
- blocked read the prices without running JavaScript
## Top issues
1. **/, /pricing turn a real browser's own request away, so the wall sits below HTTP and no crawler reaches the page.** (machine_discoverability)
2. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/hims-prs5fz
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: The next scan opens the homepage and the key pages in a real browser and under the search crawler names, and every one is served.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/hims-prs5fz
## The agent door
- **machine_discoverability** 13/100. No JSON-LD schema or microdata on the homepage. Sitemap and robots.txt exist but are blocked from automated access. A real browser is refused with an automated traffic challenge, closing the primary path for assistant shopping.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage. Automated access to all 6 standard OpenAPI paths was refused. The site publishes no developer-facing integration surface that an automated system could discover or use.
- **pricing_legibility** null/100. Could not verify: this scan did not reach the pages that would show it.
- **agent_aware_instrumentation** 8/100. No MCP manifest.
- **machine_fetchable_trust** 25/100. Security.txt could not be checked because automated access was refused. The homepage refuses automated clients outright with HTTP 403. No signature headers were sent with the homepage response.
- **commercial_rails** 10/100. .
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
