# On: agent door 44, human door not measured
- Site: on.com
- Scanned: 2026-09-04
- Scan type: Deep scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/on-3xk76g
- Scanner version: 10
On.com has a well-indexed storefront for search engines but no readable price data, no checkout route and no working policy pages for either agents or careful shoppers to act on.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 44/100 |
| Composite | 44/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 11 of 18 requests, but could not find a contact route for machines. It came up empty on 6 other checks too. That is enough missing for a machine to give up before it reaches a purchase.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- missing read a product page as data
- missing read the returns and shipping terms
- ok      walk the way a visitor would, to a signup form or a product
- ok      check if MCP manifest offers real API key onboarding
## What a visitor meets
1. **Landing page load** (blocked). Root URL redirects immediately to /en-us/shop/apparel. Rendered page is blank white. DOM text extracted shows only a newsletter email capture overlay (Email field, Subscribe button) and a footer copyright, no heading, no nav, no product content for an automated visitor.
## Top issues
1. **On.com has no published route for an agent to complete a purchase despite listing 75 product URLs in its sitemap.** (commercial_rails)
2. **No self-serve path exists for an agent to onboard against this site: no OpenAPI spec, no linked documentation, and a read-only MCP manifest.** (programmatic_onboarding)
3. **No security.txt file is published at the standard well-known path.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/on-3xk76g
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Product markup skeleton** at `/en-us/shop/womens`, 2 hours, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page.
- **Returns and refunds page** at `/returns`, 30 minutes, no developer needed. Verify: The next scan reads the returns policy page as text without JavaScript and finds it linked from a product page.
- **Shipping and delivery page** at `/shipping`, 30 minutes, no developer needed. Verify: The next scan reads the shipping policy page as text without JavaScript and finds it linked from a product page.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/on-3xk76g
## The agent door
- **machine_discoverability** 96/100. No AI crawler is blocked in robots.txt, a real browser gets the page normally, and a sitemap lists 75 URLs including product pages. llms.txt and 4 schema.org types are also published on the homepage.
- **programmatic_onboarding** 10/100. The only machine interface found is an MCP manifest exposing a single brand info tool, with no auth or key issuance. No OpenAPI spec and no linked developer docs exist, so an agent has no path to integrate.
- **pricing_legibility** null/100. Could not verify: this scan did not reach the pages that would show it.
- **agent_aware_instrumentation** 58/100. An MCP manifest is published at /.well-known/mcp.json giving agents a discoverable interface, but it exposes only brand information, not commerce or account actions.
- **machine_fetchable_trust** 40/100. No security.txt file exists at the standard path, it returns an HTML page instead. The homepage itself answers automated requests fine, but that is the only trust signal confirmed.
- **commercial_rails** 15/100. No Product schema on the 3 pages checked, no working catalog feed, and no readable UCP or commerce manifest despite a file existing at that path. Returns and shipping pages return 200 but with only 33 characters of text, so there are no.
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
