# PayPal: agent door 56, human door not measured
- Site: zettle.com
- Scanned: 2026-09-10
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/zettle-e9tapn
- Scanner version: 51
- Scanner release: 6da0c16
- Scoring methodology: 1
- Evidence schema: 1
0 human and 5 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 56/100 (5/6 dimensions) |
| Composite | 56/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The scanner recorded successful observations for 9 of 13 checks, but could not find an MCP manifest at the standard paths checked. It came up empty on 3 other checks too. 2 checks could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- ok      find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- missing find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
## Top issues
1. **No OpenAPI specification was identified at the 6 standard paths checked.** (programmatic_onboarding)
   - Evidence: No OpenAPI spec at the 6 standard paths checked (/openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /api-docs, /.well-known/openapi.json). Documentation links found: https://developer.paypal.com/home/
   - Evidence: Checked directly: /openapi.json, /openapi.yaml, /swagger.json, /api/openapi.json, /api-docs, /.well-known/openapi.json.
   - Evidence: Checked URL: https://www.paypal.com
   - Fix: Publish the API's OpenAPI document at /openapi.json or /.well-known/openapi.json and link it from the docs.
The full report is at https://www.seconddoor.io/r/zettle-e9tapn
## Files generated from this scan
- **Let verified assistants through** at `notes`, 1 hour, developer. Verify: On a subsequent scan, compare the same endpoint and client response. An unavailable check remains unresolved.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **pricing.md** at `/pricing.md`, 20 minutes, no developer needed. Verify: The next scan fetches /pricing.md as text and records pricing as machine readable.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/zettle-e9tapn
## The agent door
- **machine_discoverability** 80/100. No restriction on the tested crawler names was found in robots.txt. Our browser received a refusal or a stripped page at the checked URL. No user agent rule refused the tested retrieval crawler names.
- **programmatic_onboarding** 24/100. Authentication is documented. Endpoint examples are shown.
- **pricing_legibility** 85/100. 10 prices are readable without JavaScript. An enterprise tier routes to sales, which is standard practice and not counted against the score.
- **agent_aware_instrumentation** 8/100. No MCP manifest was identified at the discovery paths checked.
- **machine_fetchable_trust** 85/100. Security.txt is published with a contact route. The homepage answers automated requests.
- **commercial_rails** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
## The human door
- **steps_to_first_value** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **required_fields** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **verification_walls** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
- **error_recovery** not measured. Not measured: an access refusal or challenge prevented our scanner from reading the required page.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
