# SecondDoor: 2 point Door Gap
- Site: seconddoor.io
- Scanned: 2026-09-06
- Scan type: Basic scan
- Business type: hybrid
- Report: https://www.seconddoor.io/r/seconddoor-96qwx3
- Scanner version: 10
A hybrid storefront and SaaS platform with strong machine discoverability but no published agent checkout path for either funnel.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 83/100 |
| Agents | 81/100 |
| Composite | 82/100 |
| Door Gap | 2 points |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 16 of 18 requests, but could not find out whether verified agents are recognised. It came up empty on 1 other check too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- ok      find a contact route for machines
- ok      find a published agent interface
- ok      find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- ok      find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- missing read the product catalogue as data
- ok      read a product page as data
- ok      read the returns and shipping terms
- ok      find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **Shipping policy is not published at standard paths, leaving a key commercial detail unavailable to agents and customers.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/seconddoor-96qwx3
## Files generated from this scan
- **Shipping and delivery page** at `/shipping`, 30 minutes, no developer needed. Verify: The next scan reads the shipping policy page as text without JavaScript and finds it linked from a product page.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/seconddoor-96qwx3
## The agent door
- **machine_discoverability** 100/100. Robots.txt names and allows 14 AI crawlers including GPT, Claude, Perplexity and Gemini. A real browser is served normally. Sitemap lists 84 URLs. Homepage carries 6 schema.org types.
- **programmatic_onboarding** 50/100. A machine readable API spec is published.
- **pricing_legibility** 88/100. Six prices are readable without JavaScript on the pricing page: $0, $29, $99, $249, $2,500 and an unlabeled tier. No tier is gated behind a demo or contact-sales wall. FAQ markup is present. Currency is USD.
- **agent_aware_instrumentation** 100/100. MCP manifest published at /.well-known/mcp.json. AI-plugin.json published. Robots.txt explicitly names 14 AI crawlers and allows them. OpenAPI spec published. All four major instrumentation channels are active.
- **machine_fetchable_trust** 85/100. Security.txt is published with a contact route for machines. Returns policy reads as text at /refunds. Homepage answers automated requests. Shipping policy was not found at standard paths. Trust signals are present but incomplete.
- **commercial_rails** 65/100. Prices are published in raw HTML on the pricing page. A self-serve signup form is 2 steps from the homepage with 2 required fields and 1 SSO option. No UCP manifest, storefrontMCP, or payment processor was detected.
## The human door
- **steps_to_first_value** 80/100. Signup form is 2 steps from the homepage. The form itself has 2 fields, both required: work email and password. A Google SSO option is available. No payment is asked on signup. The path to account creation is direct.
- **required_fields** 93/100. The signup form has 2 fields total, both required: work email and password. Google SSO is offered as an alternative. 2 of 2 inputs carry validation rules. Friction is minimal.
- **verification_walls** 80/100. No verification requirement appears on the signup page itself. Google SSO avoids email verification entirely. The form does not ask for phone, identity verification, or payment card. Verification is not a gate to signup.
- **error_recovery** 80/100. Both form inputs carry validation rules and constraints. 2 of 2 inputs have validation attributes. No inline error containers or live regions were detected on the form, so error messaging clarity could not be verified.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
