# OtterlyAI: agent door 67, human door not measured
- Site: otterly.ai
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/otterly-rz3w42
- Scanner version: 12
A B2B SaaS platform with published pricing and API docs, but no machine-readable spec and no signup funnel to measure.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 67/100 |
| Composite | 67/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The agent got through 10 of 14 requests, but could not find a contact route for machines. It came up empty on 3 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- ok      find a comparison page worth citing
## Top issues
1. **No OpenAPI specification was found at the 4 standard paths checked, so a client must be written from prose instead of generated.** (programmatic_onboarding)
2. **No security.txt file is published, leaving no machine-readable contact point for security researchers or agents to report vulnerabilities.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/otterly-rz3w42
## Files generated from this scan
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/otterly-rz3w42
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt or user agent rules. A real browser is served the page normally. The homepage publishes 14 schema.org types including SoftwareApplication and Offer. A sitemap lists 67 URLs. llms.txt is published.
- **programmatic_onboarding** 60/100. The docs describe self serve key issuance, API credentials are documented, authentication is documented, endpoint examples are shown, code samples are provided.
- **pricing_legibility** 93/100. 33 prices are readable without JavaScript on the pricing page. No tier is gated behind a demo or sales contact. Plans are published as Offer structured data. Currency is USD. Prices range from $29 to $1,000 per month.
- **agent_aware_instrumentation** 68/100. An MCP manifest is published, developer documentation describes an API, but only in prose.
- **machine_fetchable_trust** 40/100. No security.txt is published at /.well-known/security.txt. The homepage answers automated requests with HTTP 200. No Web Bot Auth signals are present. Trust metadata is minimal.
- **commercial_rails** 40/100. Prices are published in raw HTML, the plans are published as Offer structured data.
## The human door
- **steps_to_first_value** null/100. Could not verify: this scan did not reach the pages that would show it.
- **required_fields** null/100. Could not verify: this scan did not reach the pages that would show it.
- **verification_walls** null/100. Could not verify: this scan did not reach the pages that would show it.
- **error_recovery** null/100. Could not verify: this scan did not reach the pages that would show it.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
