# Shippo: 6 point Door Gap
- Site: shippo.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: hybrid
- Report: https://www.seconddoor.io/r/shippo-b5mjfu
- Scanner version: 49
- Scanner release: c49d1def936f56a5ab0871f38c5e6412433ec37a
- Scoring methodology: 1
- Evidence schema: 1
1 human and 6 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 80/100 (1/4 dimensions) |
| Agents | 74/100 (6/6 dimensions) |
| Composite | 77/100 |
| Door Gap | 6 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 12 of 19 checks, but could not find a contact route for machines. It came up empty on 6 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- missing read a product page as data
- ok      read the returns and shipping terms
- missing discover storefront agent checkout rails
- missing find a comparison page worth citing
- ok      walk the way a visitor would, to a signup form or a product
## What a visitor meets
1. **Entry observation** (observed). Primary entry is "Get started". 2 steps from the homepage. 4 fields, 0 marked required in the visible form. 1 sign in option: google. 0 of 4 visible entry-form inputs carry validation attributes; submission was not tested.
## Top issues
1. **No Product structured data was identified in the HTTP responses for the product pages checked.** (pricing_legibility)
   - Evidence: No Product node was identified in the structured data of /products/rating-api, /products/api/addresses, /products/grow.
   - Evidence: Checked directly: /products/rating-api, /products/api/addresses, /products/grow.
   - Evidence: Checked URL: https://goshippo.com
   - Fix: Publish Product markup with offers on every product page: price, currency, availability, a brand and a GTIN or SKU.
2. **No OpenAPI specification was identified at the 6 standard paths checked.** (programmatic_onboarding)
3. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
The evidence and the recommended fix for the rest are on the report page: https://www.seconddoor.io/r/shippo-b5mjfu
## Files generated from this scan
- **Product markup skeleton** at `/products/rating-api`, 2 hours, developer. Verify: The next scan reads price, currency and availability in the Product markup of at least one product page.
- **Return policy and shipping structured data** at `product page`, 30 minutes, developer. Verify: The next scan reads a MerchantReturnPolicy on the product pages, and OfferShippingDetails when the shipping node was published.
- **Link the policy pages from the product page** at `notes`, 30 minutes, no developer needed. Verify: The next scan finds the returns and shipping policy pages linked from a product page.
- **A comparison page brief** at `/compare/shippo-vs-competitor`, 3 hours, no developer needed. Verify: The next scan finds a comparison page listed in the sitemap or linked from the homepage, and reads its text without JavaScript.
- **Agent checkout: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds a UCP manifest, a storefront MCP endpoint or another discovery file answering, and the checkout check passes.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/shippo-b5mjfu
## The agent door
- **machine_discoverability** 100/100. No restriction on the tested crawler names was found in robots.txt. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 40/100. API credentials are documented. Authentication is documented. OAuth authorization metadata is published.
- **pricing_legibility** 96/100. 5 prices are readable without JavaScript. An enterprise tier routes to sales, which is standard practice and not counted against the score. The plans are published as Offer structured data too. The pricing page carries FAQ markup.
- **agent_aware_instrumentation** 75/100. An MCP manifest is published. WooCommerce was detected; no checkout discovery interface was identified at the endpoints checked. OAuth authorization-server metadata is published; this alone does not identify an MCP endpoint.
- **machine_fetchable_trust** 65/100. No security.txt was identified at the checked path. The returns policy reads as text. The shipping policy reads as text. The homepage answers automated requests.
- **commercial_rails** 70/100. Prices are published in raw HTML. A self-serve signup entry was observed from the homepage. The plans are published as Offer structured data.
## The human door
- **steps_to_first_value** 80/100. A signup form was reached in 2 steps from the homepage.
- **required_fields** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
