agentspeed.

auth0.com

scanned 7/26/2026, 5:33:34 AM · fresh · rubric 2026.08.0
Built with Next.js
robots.txt present: passrobots.txt allows AI agents: passContent-Signal directives: failllms.txt present: passSitemap present: passLink response headers: failCanonical URL: passMCP server card: failOAuth authorization metadata: failOAuth resource metadata: failAPI catalog / OpenAPI: failWeb Bot Auth: failMarkdown negotiation: failText-to-markup ratio: failContent without JavaScript: warnHeading hierarchy: passCookie wall blocks content: passPage title: passMeta description: passJSON-LD present: passStructured data validates: passSchema type coverage: passPaywall / login wall: passAgent Skills manifest: failWebMCP actions: failPrimary action reachable: passReachability: passTime to first byte: passFull render time: skipPage weight: pass75/ 100 · C
Good

This is how AI agents (not browsers) experience auth0.com. The score weights five categories of machine-readability; the ticks on the arc are the 30 individual checks behind it.

✉ Email me this report + alert me when it changes ↓

Top fixes

Checks tagged “emerging” are 2026 agent-protocol standards most of the web hasn’t adopted yet — adopting early is an edge, not a defect.

failLink response headersDiscoverability

No HTTP Link: response headers. Emit canonical/alternate/describedby relations so HEAD-only or stream-rendering agents get them without parsing HTML.

Fix: Emit `Link:` headers for canonical, alternate-language, and describedby relations. Agents that fetch HEAD-only or stream-render rely on these.

failText-to-markup ratioReadability

Visible text is 5.3% of HTML weight (21459/403358 bytes). Low. Markup may be crowding out agent-usable text.

Fix: Heavy ad or navigation markup crowds out agent-usable text. Aim for a text-to-DOM ratio above 15%.

warnContent without JavaScriptReadability

Browser pass unavailable; HTML looks like a JS-shell (e.g. #__next / #root). Likely JS-dependent.

Fix · Next.js: Render primary content on the server: use Server Components (App Router) or getServerSideProps/SSG (Pages Router). Avoid fetching above-the-fold content in a client useEffect, since agents don’t run it.

failContent-Signal directivesemergingDiscoverability

No Content-Signal directives. Add e.g. `Content-Signal: ai-train=no, ai-summarize=yes` to declare granular AI usage policy beyond binary allow/disallow.

Fix: Add `Content-Signal:` directives to your robots.txt. This is the emerging standard (Cloudflare-driven) for declaring fine-grained AI usage policy beyond a binary allow/disallow.

failMCP server cardemergingDiscoverability

No valid MCP Server Card at /.well-known/mcp/server-card.json. Publish one so agents can discover your tools without HTML scraping.

Fix: Publish an MCP Server Card describing the tools your site exposes. Agents discover capabilities via `/.well-known/mcp/server-card.json`. See modelcontextprotocol.io for the schema.

Don’t lose this report

Get it in your inbox now — and a heads-up whenever auth0.com’s agent-readiness score changes. Free, unsubscribe anytime.

Qualifies for certificationBronze

This score clears the Bronze threshold (70+). Certification turns it into a dated, publicly verifiable attestation — a verification URL, an embeddable badge, and weekly monitoring for a full year. Scores under 70 can’t buy this, which is what makes displaying it mean something.

Get certified — $199/year →

What the agent receives

The agent’s-eye view
Secure AI Agent & User Authentication | Auth0 Login Deutsch English Français Español Português 日本語 Developers Developers Developer Center Code Samples Guides Identity Unlocked - Podcasts Zero Index Newsletter Developer Tools OIDC Connect Playground SAML Tool JWT.io Webauthn.me Get Involved Events Auth0 Research Program Documentation Documentation Auth0 Docs Articles Quickstarts APIs SDK Libraries Support Center Community Support Knowledge Base Explore Auth0 Marketplace Resources Blog Learn Intro to IAM (CIAM) Product Platform Auth0 for AI Agents Access Management Extensibility Security User Management Authentication Fine-Grained Authorization View platform Features Universal Login Embedded Login Single Sign-On Multifactor Authentication Actions Machine to Machine Passwordless Breached Passwords Token Vault Forms View features Solutions Customer Identity Trends Report 2025 Industries Retail Financial Services Nonprofits & Charities Startups Healthcare Use Cases Consumer Applications B2B SaaS Applications Blog Pricing Language Deutsch English Français Español Português 日本語 Sign up Login Let's connect Developers Developers Developer Center Code Samples Guides Identity Unlocked - Podcasts Zero Index Newsletter Developer Tools OIDC Connect Playground SAML Tool JWT.io Webauthn.me Get Involved Events Auth0 Research Program Documentation Documentation Auth0 Docs Articles Quickstarts APIs SDK Libraries Architecture Playbooks Identity for AI AI Into Production Support Center Community Support Knowledge Base Explore Auth0 Marketplace Resources BLOG Getting Unlimited Scalability with Okta Fine-Grained Authorization Blog Learn Intro to IAM (CIAM) Product Platform Auth0 for AI Agents Access Management Extensibility Security User Management Authentication Fine-Grained Authorization View platform Features Universal Login Embedded Login Single Sign-On Multifactor Authentication Actions Machine to Machine Passwordless Breached Passwords Token Vault Forms View features Technology Overview Watch a walkthrough of the Auth0 Platform Cloud Deployments Deploy to the cloud, your way Auth0 Marketplace Discover the integrations you need to solve identity Solutions Industries Retail Financial Services Nonprofits & Charities Startups Healthcare Your goals Enterprise-Grade Identity at Scale Ship AI Agents Use Cases Consumer Applications B2B SaaS Applications Case Studies Read our customers stories Customer Identity Trends Report 2025 Securing customer trust in the age of AI CIAM ROI Calculator Estimate the revenue impact to your customer-facing business AI PRODUCT INNOVATIONS New tools to safely ship and scale agentic apps Blog Pricing Sign up Let's connect Your browser does not support the video tag. New Explore Embedded Login → Secure AI agents, humans, and whatever comes next Start building for free Talk to sales Auth0 for AI Agents Named Most Innovative AI Infrastructure Security Solution 2026 Read Customer Stories Read Customer Stories Auth0 is an easy to implement, adaptable authentication and authorization platform SECURITY BUILT-IN 3 billion+ attacks blocked each month* *by Okta (Auth0 and Okta platforms) Always-on performance 99.99% uptime Scalable 10 billion+ authentications every month Javascript iOS (Swift) Android (Kotlin) Angular Copied to clipboard Integrate Auth0 in any application in just 5 minutes With a few lines of code you can have Auth0 integrated in any app written in any language, and any framework. We provide 30+ SDKs & Quickstarts to help you succeed on your implementation. See all quickstarts Built for what you’re building AI Agents AI TOOLS B2B B2C AI Agents AI TOOLS B2B B2C Secure your AI Agents Authenticate the user Secure the human who is prompting the agent in the first place. Control the tools Use our Token Vault to manage which APIs your agent can call on the user's behalf. Limit the knowledge Apply fine-grained authorization directly to your RAG pipelines. Featured capabilities Token Vault User Authentication Async Authorization FGA for RAG Learn more Safeguard internal AI tools Build internal apps, fast Add enterprise-grade auth to internal dashboards, AI apps, and tools in minutes. Easy, secure auth for all Use SSO and M2M authentication to better secure humans, machines, AI agents, and MCP servers. Manage access automatically Automate provisioning and fine-tune access as your team and tools evolve. Featured CAPABILITIES SSO Token Vault M2M Authentication Fine-Grained Authorization (FGA) SCIM Unlock enterprise deals Build with robust APIs & SDKs Get full control without the heavy lifting. Deploy enterprise features Add SSO and SCIM with a simple toggle, making you enterprise-grade, right out of the box. Now free. Speed up sales Make it painless for IT buyers with automated setup and session control. Featured capabilities Multi-tenancy Fine-Grained Authorization Enterprise Connections Express Configuration Delegated Admin Universal Logout Get started for free More signups. Less friction. Orchestrate tailored journeys Sign-up, login, and re-engagement powered by APIs, Forms, and Actions. Protect with ease Give customers fast, passwordless logins. Adaptive MFA and bot detection keep things safe without getting in their way. Connect experiences Extend identity to mobile apps, point-of-sale, and other connected devices. Featured capabilities Passwordless Embedded Login User Authentication Multi-Factor Authentication Single Sign-On Bot Detection Learn more Built for what you’re building Built for AI Agents Built for AI TOOLS Built for B2B Built for B2C Secure your AI Agents Authenticate the user Secure the human who is prompting the agent in the first place. Control the tools Use our Token Vault to manage which APIs your agent can call on the user's behalf. Limit the knowledge Apply fine-grained authorization directly to your RAG pipelines. Featured capabilities Token Vault User Authentication Async Authorization FGA for RAG Learn more Safeguard internal AI tools Build internal apps, fast Add enterprise-grade auth to internal dashboards, AI apps, and tools in minutes. Easy, secure auth for all Use SSO and M2M authentication to better secure humans, machines, AI agents, and MCP servers. Manage access automatically Automate provisioning and fine-tune access as your team and tools evolve. Featured CAPABILITIES SSO Token Vault M2M Authentication Fine-Grained Authorization (FGA) SCIM Unlock enterprise deals Build with robust APIs & SDKs Get full control without the heavy lifting. Deploy enterprise features Add SSO and SCIM with a simple toggle, making you enterprise-grade, right out of the box. Now free. Speed up sales Make it painless for IT buyers with automated setup and session control. Featured capabilities Multi-tenancy Fine-Grained Authorization Enterprise Connections Express Configuration Delegated Admin Universal Logout Get started for free More signups. Less friction. Orchestrate tailored journeys Sign-up, login, and re-engagement powered by APIs, Forms, and Actions. Protect with ease Give customers fast, passwordless logins. Adaptive MFA and bot detection keep things safe without getting in their way. Connect experiences Extend identity to mobile apps, point-of-sale, and other connected devices. Featured capabilities Passwordless Embedded Login User Authentication Multi-Factor Authentication Single Sign-On Bot Detection Learn more You’re in great company Auth0 lets Philips Hue focus on R&D, not IAM Auth0 enabled us to reduce our IAM-related development and maintenance by 80%, freeing us to focus on new lighting and security offerings that truly differentiate our products rather than reinventing the IAM wheel. “We used Auth0 from day one to be able to spend our limited time on innovating and creating new user experiences rather than building another user authentication system.“ Ardy Naghshineh Founder and CEO “As we’re growing with these customers, something that’s very clear is that big custome

Show your score

Embed this badge on your site. It links back to this live scan and updates on every rescan.

AgentSpeed score for auth0.com
<a href="https://agentspeed.com/scan/auth0.com"><img src="https://agentspeed.com/badge/auth0.com" alt="AgentSpeed agent-readiness score" height="56"></a>

Track this score

Get this report by email, then a heads-up when auth0.com’s agent-readiness actually changes — a check regressing, or the composite dropping.

Two things never trigger an email: a score change caused by us publishing a new rubric, because that is a different instrument rather than a change to your site, and movement explained only by timing-derived checks, which shift run to run on a site nobody touched.

Want it on your own schedule, with Slack or a webhook instead of email? Score-drift monitoring is on every paid plan.

This score says whether an AI agent could read auth0.com. AI traffic analytics says whether one actually came — and which pages turned it away.

Full breakdown

17 pass1 warn11 fail1 skip
Discoverability
pass
robots.txt present
A robots.txt is reachable at the site root.
100/100
pass
robots.txt allows AI agents
All 9 answer-time access agents allowed.
100/100
fail
Content-Signal directivesemerging
No Content-Signal directives. Add e.g. `Content-Signal: ai-train=no, ai-summarize=yes` to declare granular AI usage policy beyond binary allow/disallow.
0/100
pass
llms.txt present
Found /llms.txt (4232 bytes), H1 + at least one link present. Not scored.
100/100
pass
Sitemap present
sitemap.xml reachable and referenced from robots.txt.
100/100
fail
Link response headers
No HTTP Link: response headers. Emit canonical/alternate/describedby relations so HEAD-only or stream-rendering agents get them without parsing HTML.
0/100
pass
Canonical URL
Canonical points to self: https://auth0.com/.
100/100
fail
MCP server cardemerging
No valid MCP Server Card at /.well-known/mcp/server-card.json. Publish one so agents can discover your tools without HTML scraping.
0/100
fail
OAuth authorization metadataemerging
No RFC 8414 metadata at /.well-known/oauth-authorization-server. Agents that act on behalf of users need this to discover your authorization endpoints.
0/100
fail
OAuth resource metadataemerging
No RFC 9728 metadata at /.well-known/oauth-protected-resource. Publish it so agents can discover required scopes without hand-coded credentials.
0/100
fail
API catalog / OpenAPIemerging
No /.well-known/api-catalog (RFC 9727) and no /openapi.json|yaml. Publish one so agents that integrate with APIs can discover your endpoints.
0/100
fail
Web Bot Authemerging
No Web Bot Auth JWKS at /.well-known/http-message-signatures-directory.json. Publish one to allow trusted agents while keeping a default-deny posture for the rest.
0/100
Readability
fail
Markdown negotiationemerging
Accept: text/markdown returns HTML, not markdown. Serve a markdown variant of primary content when requested; agents summarize and cite it more reliably.
0/100
fail
Text-to-markup ratio
Visible text is 5.3% of HTML weight (21459/403358 bytes). Low. Markup may be crowding out agent-usable text.
40/100
warn
Content without JavaScript
Browser pass unavailable; HTML looks like a JS-shell (e.g. #__next / #root). Likely JS-dependent.
50/100
pass
Heading hierarchy
Hierarchy is well-formed (1 H1, no skipped levels, 52 headings total).
100/100
pass
Cookie wall blocks content
No common consent-modal markers detected.
100/100
pass
Page title
A concise <title> is present (45 chars).
100/100
pass
Meta description
A well-sized meta description is present (134 chars).
100/100
Structured data
pass
JSON-LD present
Found 1 JSON-LD block.
100/100
pass
Structured data validates
4/4 checkable block(s) validated cleanly against schema.org. 1 block(s) skipped — type outside the set we check.
100/100
pass
Schema type coverage
Page intent unclear; no specific schema.org type expected.
100/100
Actionability
pass
Paywall / login wall
No paywall or login-wall detected on the landing URL.
100/100
fail
Agent Skills manifestemerging
No Agent Skills manifest at /.well-known/agent-skills.json. Enumerate the tasks agents can perform (search, add-to-cart, contact-support) so they pick the right one without scraping.
0/100
fail
WebMCP actionsemerging
No WebMCP detected. On pages with first-class actions (cart, support, account), embed a WebMCP server so on-page agents invoke tools directly.
0/100
pass
Primary action reachable
Primary offering identified ("Authentication and authorization platform") with price/CTA ("Start building for free").
100/100
pass
Reachability
HTTP 200.
100/100
Performance
pass
Time to first byte
TTFB 252ms. Healthy.
80/100
skip
Full render time
Full-render time unavailable (browser pass skipped or failed).
pass
Page weight
Initial document is a lean 394 KB.
100/100
Beyond the scan

Running AI agents of your own? AgentSpeed also monitors them in production — every run, its latency, cost, and failures, with alerts when something breaks. Free for 10,000 events a month, no credit card.

Start watching free →See plans