# Tonal: 32 point Door Gap
- Site: tonal.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: hybrid
- Report: https://www.seconddoor.io/r/tonal-m6g93x
- Scanner version: 49
- Scanner release: c49d1def936f56a5ab0871f38c5e6412433ec37a
- Scoring methodology: 1
- Evidence schema: 1
1 human and 4 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 95/100 (1/4 dimensions) |
| Agents | 63/100 (4/6 dimensions) |
| Composite | 79/100 |
| Door Gap | 32 points |
The human score is the mean of the measured human dimensions, the agent score the mean of the measured agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The scanner recorded successful observations for 8 of 15 checks, but could not find a contact route for machines. It came up empty on 6 other checks too. 4 checks could not be measured; see the report limitations.
- ok      find out whether machines are welcome
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the prices without running JavaScript
- ok      read the product catalogue as data
- ok      read a product page as data
- missing read the returns and shipping terms
- ok      discover storefront agent checkout rails
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **No review text was identified in the server HTML of the product pages checked.** (pricing_legibility)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/tonal-m6g93x
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: On a subsequent scan, compare the same endpoint and client response. An unavailable check remains unresolved.
- **Complete product markup for Pilates Loops + Ankle Straps Bundle** at `/products/loops-straps-bundle`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete product markup for Pilates Loops - Colors** at `/products/pilates-loops-colors`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete product markup for Tonal Grip Socks** at `/products/tonal-grip-socks`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in this Product markup, with the structured price matching the catalogue feed.
- **Complete the merchant fields in product markup** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in the Product markup it samples.
- **Put Trustpilot reviews in the page** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds review text in the server HTML of a product page.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **OpenAI product feed** at `openai-product-feed.tsv`, 20 minutes, no developer needed. Verify: The next scan finds a valid GTIN and a brand on the sampled variants and the product pages carry the fields a feed listing needs.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/tonal-m6g93x
## The agent door
- **machine_discoverability** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **programmatic_onboarding** 42/100. No general API documentation or OpenAPI specification was identified through the paths checked. A storefront MCP endpoint answered the tested tools/list discovery request; authentication and use were not tested.
- **pricing_legibility** 83/100. Product-associated price evidence was identified in the HTTP responses from the 3 product pages checked. Product structured data publishes price and currency, so an agent can parse cost without scraping. Availability is published too.
- **agent_aware_instrumentation** 61/100. No MCP manifest was identified at the discovery paths checked. A Universal Commerce Protocol manifest is published. A storefront MCP endpoint answered the tested tools/list request. The catalogue answers as data at /products.json.
- **machine_fetchable_trust** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **commercial_rails** 66/100. Product markup carries price and currency. The catalogue answers as data, which a feed can be built from. A Shopify storefront; product identifier and brand coverage were checked. A UCP manifest publishes how to transact, a bonus.
## The human door
- **steps_to_first_value** 95/100. A product priced at $150.00 was reached in 2 steps; a purchase control was visible.
- **required_fields** not measured. Not measured: this scan did not reach the page or action needed to verify it.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
