# Tink: 56 point Door Gap
- Site: tink.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/tink-ydb7ts
- Scanner version: 49
- Scanner release: c49d1def936f56a5ab0871f38c5e6412433ec37a
- Scoring methodology: 1
- Evidence schema: 1
1 human and 6 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 80/100 (1/4 dimensions) |
| Agents | 24/100 (6/6 dimensions) |
| Composite | 52/100 |
| Door Gap | 56 points |
| Percentile | 2nd |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 3 of 14 checks, but could not find out whether machines are welcome. It came up empty on 10 other checks too. 1 check could not be measured; see the report limitations.
- ok      reach the site at all
- missing find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- missing read the site's own guide for language models
- missing find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- missing read the prices without running JavaScript
- ok      walk the way a visitor would, to a signup form or a product
## What a visitor meets
1. **Entry observation** (observed). Primary entry is "Create account". 2 steps from the homepage. 6 fields, 0 marked required in the visible form. 0 of 6 visible entry-form inputs carry validation attributes; submission was not tested.
## Top issues
1. **No OpenAPI specification was identified at the 6 standard paths checked.** (programmatic_onboarding)
   - Evidence: No OpenAPI spec at the 6 standard paths checked (/openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /api-docs, /.well-known/openapi.json). Documentation links found: https://docs.tink.com/api, https://docs.tink.com/resources/landing/make-your-first-api-call, https://docs.tink.com/
   - Evidence: Checked directly: /openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /api-docs, /.well-known/openapi.json.
   - Evidence: Checked URL: https://tink.com
   - Fix: Publish the API's OpenAPI document at /openapi.json or /.well-known/openapi.json and link it from the docs.
2. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
3. **No valid llms.txt was identified at the site root.** (machine_discoverability)
The evidence and the recommended fix for the rest are on the report page: https://www.seconddoor.io/r/tink-ydb7ts
## Files generated from this scan
- **A pricing page that states a price** at `/pricing.md`, 1 hour, no developer needed. Verify: The next scan reads at least one price in the raw HTML of the pricing page.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **sitemap.xml** at `/sitemap.xml`, 20 minutes, no developer needed. Verify: The next scan fetches /sitemap.xml, finds a urlset, and the sitemap check passes.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
- **llms.txt** at `/llms.txt`, 15 minutes, no developer needed. Verify: The next scan fetches /llms.txt as text and the llms.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/tink-ydb7ts
## The agent door
- **machine_discoverability** 50/100. No restriction on the tested crawler names was found in robots.txt. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 10/100. No API interface was identified through the discovery paths and homepage links checked.
- **pricing_legibility** 12/100. No prices anywhere on the pricing page, and the copy routes to sales.
- **agent_aware_instrumentation** 8/100. No MCP manifest was identified at the discovery paths checked.
- **machine_fetchable_trust** 40/100. No security.txt was identified at the checked path. The homepage answers automated requests.
- **commercial_rails** 25/100. The pricing page includes a sales route and no prices were identified in its raw HTML. A self-serve signup entry was observed from the homepage.
## The human door
- **steps_to_first_value** 80/100. A signup form was reached in 2 steps from the homepage.
- **required_fields** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
