# Quip: 17 point Door Gap
- Site: quip.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/quip-dbc5fx
- Scanner version: 12
Quip publishes prices and a signup form but blocks agents from obtaining API credentials or reading developer documentation.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 68/100 |
| Agents | 51/100 |
| Composite | 60/100 |
| Door Gap | 17 points |
| Percentile | 37th |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 7 of 15 requests, but could not read the site's own guide for language models. It came up empty on 7 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- missing find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No comparison or alternatives page exists, which is the page an assistant cites when a buyer asks it to shortlist vendors.** (machine_discoverability)
2. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
3. **No comparison or alternatives page is published, so agents cannot find Quip when shortlisting vendors in a category.** (machine_discoverability)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/quip-dbc5fx
## Files generated from this scan
- **Pricing as Offer structured data** at `pricing page`, 20 minutes, developer. Verify: The next scan reads Offer structured data with a price and currency on the pricing page, and the pricing check credits it.
- **A comparison page brief** at `/compare/quip-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/quip-dbc5fx
## The agent door
- **machine_discoverability** 97/100. No AI crawler is blocked by robots.txt or user agent rules, a real browser is served the page normally, and a sitemap lists 93 URLs. The homepage renders in 181ms and serves key pages without JavaScript.
- **programmatic_onboarding** 10/100. No API surface was found in the documentation that was linked and fetched.
- **pricing_legibility** 85/100. Five prices are readable without JavaScript on the pricing page at quip.com/about/pricing: $10, $30, $12, $25, and $100. All are per-seat. An enterprise tier routes to sales contact, which is standard practice.
- **agent_aware_instrumentation** 8/100. No MCP manifest is published at any of the 3 standard paths checked. No ai-plugin.json or Web Bot Auth signals are present. An agent cannot invoke Quip as a tool or integrate it into an agentic workflow without manual configuration.
- **machine_fetchable_trust** 40/100. No security.txt file is published at /.well-known/security.txt. The homepage answers automated requests and serves HTTP 200, but no machine-readable security policy, vulnerability disclosure route, or contact information for security.
- **commercial_rails** 65/100. Prices are published in raw HTML on the pricing page and a self-serve signup form is reachable from the homepage in 2 steps. The form asks for 1 field with 0 required fields, so a visitor can enter the product without payment information.
## The human door
- **steps_to_first_value** 80/100. The primary call to action, 'Get started with any use-case', reaches a signup form in 2 steps from the homepage. The form contains 1 field with 0 required fields, so a human can proceed without friction.
- **required_fields** 90/100. The signup form on the entry path contains 1 field total, and 0 of those fields are marked as required. A visitor can submit the form without entering any data, removing a common friction point in the onboarding flow.
- **verification_walls** 65/100. No verification requirement, email confirmation demand, or CAPTCHA is visible on the signup page itself. However, the walk did not observe the post-submission flow, so verification gates that appear after form submission cannot be ruled.
- **error_recovery** 35/100. Of the 9 inputs on the signup page, 0 carry validation rules such as type, pattern, or required attributes. The page includes 4 live regions for dynamic content but 0 inline error containers.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
