# Ritual: 8 point Door Gap
- Site: ritual.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/ritual-9r3hta
- Scanner version: 12
A Shopify storefront with agent checkout capability but no API documentation for programmatic product discovery.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 73/100 |
| Agents | 65/100 |
| Composite | 69/100 |
| Door Gap | 8 points |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 11 of 17 requests, but could not find a contact route for machines. It came up empty on 5 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **The visible product price on the storefront differs from the structured price in the product markup, creating ambiguity about which price applies at checkout.** (pricing_legibility)
2. **No developer documentation is linked from the homepage, in raw HTML or the rendered page, so integration starts with a search engine.** (programmatic_onboarding)
3. **No API documentation is published, forcing agents to discover the /products.json endpoint by reverse-engineering or prior knowledge rather than following a documented interface.** (programmatic_onboarding)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/ritual-9r3hta
## Files generated from this scan
- **Product markup for Women’s Multivitamin 18+** at `/products/essential-for-women-multivitamin`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page, with the structured price matching the catalogue feed.
- **Product markup for Men’s Multivitamin 18+** at `/products/essential-multivitamin-for-men`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page, with the structured price matching the catalogue feed.
- **Product markup for Synbiotic+** at `/products/synbiotic-plus-for-gut-health`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page, with the structured price matching the catalogue feed.
- **Product markup snippet for every product page** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads price, currency and availability in the Product markup of every product page it samples, with the structured price matching the catalogue feed.
- **Put Okendo reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **robots.txt rules for AI crawlers** at `/robots.txt`, 10 minutes, no developer needed. Verify: The next scan reads robots.txt and finds every search and agent crawler allowed, none of them kept off product or pricing paths.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **Shipping and delivery page** at `/policies/shipping-policy`, 30 minutes, no developer needed. Verify: The next scan reads the shipping policy page as text without JavaScript and finds it linked from a product page.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/ritual-9r3hta
## The agent door
- **machine_discoverability** 100/100. No AI crawler is blocked by robots.txt or user agent rules; llms.txt is published; the catalogue answers as data at /products.json with 12 products; the sitemap lists 33 URLs including product pages; 3 schema.org types on the homepage; a.
- **programmatic_onboarding** 10/100. No API documentation is linked from the homepage or discoverable at standard paths. The site publishes a UCP manifest for agent checkout but offers no developer guide to programmatic product access, leaving an agent to reverse-engineer the.
- **pricing_legibility** 83/100. 31 prices appear in the homepage HTML; 42 prices across 3 product pages without JavaScript; Product structured data carries price in USD and currency; availability is published; a GTIN identifies each product.
- **agent_aware_instrumentation** 57/100. A Universal Commerce Protocol manifest at version 2026-08-25 declares 8 capabilities and 3 payment handlers; a storefront MCP endpoint answers agent calls; the catalogue answers as data at /products.json.
- **machine_fetchable_trust** 55/100. No security.txt is published at /.well-known/security.txt. The returns policy reads as text with a 30-day window at /policies/refund-policy. The shipping policy was not found at usual paths.
- **commercial_rails** 87/100. Product markup carries price, currency, GTIN and brand; the catalogue answers as data at /products.json, which a feed can be built from; a Shopify store with GTIN and brand on its products, which Shopify Catalog syndicates; an aggregate.
## The human door
- **steps_to_first_value** 95/100. A product with its price ($26.40) and an add-to-cart control is two steps from the homepage. No variant choosers block the path. The product page renders its structured data with price, currency and availability.
- **required_fields** 80/100. Nothing on the product page demands an account before buying. The entry path walk found 6 inputs on the form with 1 carrying a validation constraint. PayPal wallet skips the form entirely. No sign-in requirement appears before checkout.
- **verification_walls** 75/100. No sign-in requirement appears on the product page or the entry path. The add-to-cart control is immediately available. A guest checkout path exists, though the walk did not complete the transaction to confirm what verification steps.
- **error_recovery** 43/100. 1 of 6 inputs on the product page carry validation rules. 15 inline error containers are present in the markup, and 18 live regions support screen readers, but the walk did not trigger validation errors to observe recovery behaviour.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
