stripe.dev Website
39 global-ready
relative to the checks that apply to this site, including 3 hosts it declares (see Declared hosts); global measures it against a maximally agent-ready site. Website https://stripe.dev/. Global keeps the 17 checks this audit could not run in its maximum.
Declared hosts
stripe.dev points agents to these hosts; results from the hosts anc could confirm are credited to stripe.dev.
server card (
transport.url)mcp.stripe. com evaluated
confirmed by RFC 9728 metadata
api-catalog anchor
api.stripe. com evaluated
OpenAPI description found
api-catalog anchor
connect.stripe. com not followed: no service description
api-catalog anchor
mcp.stripe. com not followed: no service description
api-catalog service-desc
raw.githubusercontent. com https:// raw. githubusercontent. com/ stripe/ openapi/ master/ openapi/ spec3. json evaluated
Checks by category
-
C1
partial
Discoverability
4 / 6 checks pass
/robots.txt present SHOULD PASS
Goal: Publish robots.txt and state your crawl policy explicitly.
Result: Verified (https://stripe.dev/robots.txt -> 200)
/sitemap.xml present MAY PASS
Goal: Publish sitemap.xml so agents can enumerate your content URLs.
Result: Verified (https://stripe.dev/sitemap.xml -> 200)
Resources: sitemaps.org · Fix skill
Homepage sends RFC 8288 Link headers pointing at agent resources SHOULD PASS
Goal: Advertise machine surfaces in a Link response header on / for header-only discovery.
Result: Verified (https://stripe.dev/ -> 200)
Resources: RFC 8288 (Link) · RFC 8631 (service links) · RFC 9727 (api-catalog) · Fix skill
Root HTML links to machine surfaces via <link rel> SHOULD MISSING
Goal: Point link rel elements at your machine surfaces from the root HTML head.
Result: Not found (https://stripe.dev/ -> 200 (body no match /rel=["'](service-desc|service-doc|alternate)["']/))
Fix: Add `<link rel>` elements in your root HTML head pointing at your machine surfaces: `rel="service-desc"` to the OpenAPI doc, `rel="service-doc"` to human docs, and `rel="alternate"` to `llms.txt` and the MCP card. An agent that lands on the HTML can then discover the structured surfaces without scraping.
Resources: RFC 8631 (service-desc/doc) · Fix skill
Unknown paths return HTTP 404 or 410 SHOULD PASS
Goal: Return a real HTTP 404 or 410 for unknown paths instead of a 200 SPA shell.
Result: Verified (https://stripe.dev/anc-web-audit-no-such-page -> 404)
Resources: RFC 9110 status codes · Fix skill
404 body is markdown with a recovery link SHOULD MISSING
Goal: Serve a short markdown 404 that links at least one agent recovery surface.
Result: Not found (https://stripe.dev/anc-web-audit-no-such-page -> 404 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))
Fix: When `Accept: text/markdown` hits an unknown path, return 404 or 410 with a short markdown body that includes at least one recovery link: sitemap, `llms.txt`, a docs index, or an equivalent same-origin href. Linking both sitemap and `llms.txt` as absolute URLs is the stronger pattern. Zero links is a miss even when the status is correct.
Resources: llmstxt.org · Fix skill
DNS for AI Discovery (DNS-AID) records under _agents (IETF draft) MAY N/A
Goal: Publish DNSSEC-signed SVCB records under _agents for DNS-level agent discovery.
Result: Not implemented, optional (no DNS-AID records)
Resources: DNS-AID draft · Fix skill
-
C2
partial
Content for agents
9 / 11 checks pass
/llms.txt present with a summary and link index SHOULD PASS
Goal: Serve /llms.txt with a title, summary, and categorized link index.
Result: Verified (https://stripe.dev/llms.txt -> 200)
Resources: llmstxt.org · Fix skill
/llms-full.txt present (single-fetch full corpus) MAY PASS
Goal: Serve the whole docs corpus as markdown at /llms-full.txt for one-fetch ingestion.
Result: Verified (https://stripe.dev/llms-full.txt -> 200)
Resources: llmstxt.org · Fix skill
Accept text/markdown content negotiation returns markdown SHOULD PASS
Goal: Honor Accept text/markdown on content URLs with raw markdown, not HTML chrome.
Result: Verified (https://stripe.dev/ -> 200)
Resources: RFC 7763 (text/markdown) · Fix skill
llms.txt has H1, summary, and a link index SHOULD PASS
Goal: Structure /llms.txt with an H1, a blockquote summary, and a markdown link index.
Result: Verified (https://stripe.dev/llms.txt -> error)
Resources: llmstxt.org · Fix skill
llms.txt has a when-to-use or programmatic-access section SHOULD MISSING
Goal: Tell agents when to use the MCP or docs from a short llms.txt heading.
Result: Not found (https://stripe.dev/llms.txt -> error (no when-to-use heading))
Fix: Add a heading such as `## When to use` or `## Programmatic access` with a few lines on when an agent should connect (for example: "Use the MCP when you need to search or score a CLI"). The audit looks for that heading; it does not grade the prose with an LLM.
Resources: llmstxt.org · Fix skill
Per-section llms-full.txt files resolve under content subdirectories MAY N/A
Goal: Serve a scoped llms-full.txt corpus inside each major content section.
Result: Not implemented, optional (https://stripe.dev/blog/llms-full.txt -> 404)
Resources: llmstxt.org · Fix skill
Bare CLI User-Agent receives the markdown twin MAY N/A
Goal: Serve the markdown twin to shell HTTP clients that state no content-type preference.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))
Resources: RFC 7763 (text/markdown) · RFC 9110 (User-Agent) · Fix skill
Negotiated responses carry Vary Accept, User-Agent SHOULD MISSING
Goal: Emit Vary Accept, User-Agent so shared caches never serve one client the wrong variant.
Result: Not found (https://stripe.dev/ -> 200 (header vary no match /accept(?:user-agent|[^-\n\r\u2028\u2029].*user-agent)|user-agent.*accept(?:[^-]|$)/))
Fix: When the same URL serves HTML or markdown depending on the request, emit `Vary: Accept, User-Agent` on every response. Without it a shared cache (a CDN or a corporate proxy) can store the markdown twin under the bare URL and then hand it to a browser, or vice versa. Listing both request headers you negotiate on tells every cache to key its stored copies by them, so each client class gets the variant it asked for. If the CDN ignores or strips Vary (Cloudflare's zone cache historically keeps only `Accept-Encoding`), do not give that cache a long `s-maxage` on negotiated responses — otherwise HIT replies reach clients with no Vary and the check still fails.
Resources: RFC 9110 (Vary) · Fix skill
Per-section llms.txt files resolve under content subdirectories MAY N/A
Goal: Serve a scoped llms.txt inside each major content section.
Result: Not implemented, optional (https://stripe.dev/blog/llms.txt -> 404)
Resources: llmstxt.org · Fix skill
Root HTML has a descriptive <meta name="description"> SHOULD PASS
Goal: Add a meta description naming what the service does and its agent entry points.
Result: Verified (https://stripe.dev/ -> 200)
Resources: MDN meta description · Fix skill
Root HTML embeds Schema.org JSON-LD MAY N/A
Goal: Embed Schema.org JSON-LD so agents get typed facts without inference.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (body no match /application/ld\+json/))
Resources: Schema.org · Fix skill
Root HTML has an H1 and readable text without JavaScript SHOULD PASS
Goal: Put an H1 and enough visible text in the raw root HTML that a non-JS agent can read the page.
Result: Verified (https://stripe.dev/ -> 200)
Resources: llmstxt.org · Fix skill
Root HTML uses semantic landmarks MAY PASS
Goal: Use semantic landmarks so the HTML path is parseable structure, not div soup.
Result: Verified (https://stripe.dev/ -> 200)
Resources: MDN content sectioning · Fix skill
Root HTML has a <noscript> with machine entry points SHOULD PASS
Goal: Give non-JS agents a noscript block listing your machine entry points.
Result: Verified (https://stripe.dev/ -> 200)
Resources: MDN noscript · Fix skill
Accept text/plain returns the markdown twin MAY N/A
Goal: Treat Accept text/plain as a request for the raw markdown source.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))
Resources: RFC 7763 (text/markdown) · Fix skill
AI user-fetch User-Agent receives the markdown twin MAY N/A
Goal: Serve the markdown twin to AI on-demand user-fetchers that state no content-type preference.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (content-type "text/html; charset=utf-8" !~ /markdown|text/plain/))
Resources: RFC 7763 (text/markdown) · OpenAI bots and User-Agents · Fix skill
Markdown twin carries YAML frontmatter MAY N/A
Goal: Prefix the markdown twin with a YAML frontmatter block so agents read page metadata without parsing the body.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (no leading frontmatter fence))
Resources: YAML front matter (Jekyll) · RFC 7763 (text/markdown) · Fix skill
llms.txt links resolve SHOULD PASS
Goal: Make every markdown href in /llms.txt https and fetchable.
Result: Verified (https://stripe.dev/blog/index.html.md -> 200)
Resources: llmstxt.org · Fix skill
-
C3
pass
Bot & crawl policy
3 / 3 checks pass
AI user-fetch User-Agent can reach the homepage SHOULD PASS
Goal: Let on-demand user-fetchers GET / with Accept */* and receive 2xx, not a challenge page.
Result: Verified (https://stripe.dev/ -> 200)
Resources: OpenAI user-fetchers · Fix skill
robots.txt declares AI-crawler rules (RFC 9309) SHOULD PASS
Goal: State your AI-crawler policy in robots.txt with explicit User-agent rules.
Result: Verified (https://stripe.dev/robots.txt -> 200)
robots.txt declares Content-Signal AI-usage preferences SHOULD PASS
Goal: Declare Content-Signal AI-usage preferences in robots.txt.
Result: Verified (https://stripe.dev/robots.txt -> 200)
Resources: contentsignals.org · Fix skill
Web Bot Auth signature directory present (informational) MAY N/A
Goal: Publish an HTTP Message Signatures directory if your site sends signed bot traffic.
Result: Not implemented, optional (https://stripe.dev/.well-known/http-message-signatures-directory -> 404 (status 404 not in [200]))
Resources: Web Bot Auth draft · Fix skill
-
C4
partial
API
3 / 4 checks pass
An OpenAPI description is published MUST PASS
Evaluated at
raw.githubusercontent.comGoal: Publish an OpenAPI description so non-MCP agents can call your HTTP API.
Result: Verified (https://raw.githubusercontent.com/stripe/openapi/master/openapi/spec3.json -> 200)
Resources: OpenAPI 3.1 · Fix skill
Referenced JSON Schemas resolve as application/schema+json MAY N/A
Goal: Serve the JSON Schemas your API references so agents can validate payloads pre-flight.
Result: Not applicable (no JSON Schema references detected)
Resources: JSON Schema · Fix skill
/.well-known/api-catalog published (RFC 9727) MAY PASS
Goal: Serve an RFC 9727 api-catalog linkset indexing your API descriptions.
Result: Verified (https://stripe.dev/.well-known/api-catalog -> 200)
API client errors return JSON, not HTML SHOULD PASS
Evaluated at
api.stripe.comGoal: Return a JSON error body on client-error API responses so agents can parse the failure.
Result: Verified (https://api.stripe.com/anc-web-audit-no-such-api -> 404)
Resources: RFC 9457 (problem+json) · Fix skill
API responses advertise rate-limit headers SHOULD MISSING
Evaluated at
api.stripe.comGoal: Advertise remaining quota on API responses so agents can back off instead of retrying blindly.
Result: Not found (https://api.stripe.com/anc-web-audit-no-such-api -> 404 (no rate-limit header))
Fix: Send IETF RateLimit headers (`RateLimit-Limit`, `RateLimit-Remaining`, `RateLimit-Reset`) or the common `X-RateLimit-*` aliases on API responses. A 429 should also carry `Retry-After`. Without them an agent has no budget and will retry until it is locked out.
Resources: IETF RateLimit header draft · Fix skill
-
C5
pass
MCP
5 / 5 checks pass · 17 not run
Evaluated at
mcp.stripe.com, declared by stripe.dev's server card (transport.url)Every MCP server
5 / 5 passtransport, discovery, and card checks that apply whichever protocol the server speaks
GET on the MCP endpoint answers fast (not a held-open hang) SHOULD PASS
Goal: Answer GET on the MCP endpoint fast (a fast-fail status or a documented surface), never a held-open hang.
Result: Verified (https://mcp.stripe.com/ -> 401)
Resources: MCP transports · Fix skill
CORS preflight (OPTIONS) succeeds with Access-Control-Allow-* headers SHOULD N/A
Goal: Serve one consistent CORS posture on the MCP endpoint, full preflight support or none.
Result: Deliberate posture, not scored (no Allow-Origin on the preflight or the POST: consistent no-CORS posture)
Resources: MDN CORS preflight · Fix skill
POST response carries Access-Control-Allow-Origin SHOULD N/A
Goal: Mirror the declared CORS posture on the actual MCP POST response.
Result: Deliberate posture, not scored (no Allow-Origin on the preflight or the POST: consistent no-CORS posture)
A .well-known MCP server card is published (SEP-1649) SHOULD PASS
Evaluated at
stripe.devGoal: Publish an MCP server card at the canonical SEP-1649 path.
Result: Verified (https://stripe.dev/.well-known/mcp/server-card.json -> 200)
Legacy MCP card paths redirect to the canonical card MAY N/A
Evaluated at
stripe.devGoal: Point every legacy MCP card path at the canonical card instead of serving its own copy.
Result: Not implemented, optional (https://stripe.dev/.well-known/mcp -> 404 (404 alias not published))
A human/agent usage doc for the server resolves MAY N/A
Evaluated at
stripe.devGoal: Publish a one-fetch markdown usage doc for your MCP server.
Result: Not implemented, optional (https://stripe.dev/mcp-skill.md -> 404 (status 404 not in [200]))
Resources: anc.dev example · Fix skill
a 401 names the RFC 9728 metadata in its WWW-Authenticate challenge MAY PASS
Goal: Name your protected-resource metadata in the WWW-Authenticate challenge of every 401.
Result: Verified (resource_metadata names https://mcp.stripe.com/.well-known/oauth-protected-resource)
Resources: MCP authorization · RFC 9728 section 5.1 · Fix skill
protected-resource metadata lists public https authorization_servers MAY PASS
Goal: List the authorization servers that issue tokens for your MCP server in its RFC 9728 metadata.
Result: Verified (authorization_servers: https://access.stripe.com/mcp)
Resources: RFC 9728 section 2 · MCP authorization · Fix skill
a tools/list without an access token is refused with 401 MAY PASS
Goal: Refuse every MCP request that carries no access token with 401.
Result: Verified (refused with 401)
Resources: MCP authorization · Fix skill
Legacy lane · 2025-06-18
10 not runinitialize, then a session
10 checks not run: mcp.stripe.com requires sign-in N/A
anc's public audit holds no sign-in for mcp.stripe.com.
initialize handshake returns serverInfo + protocolVersion MUST N/A
Goal: Answer JSON-RPC initialize with serverInfo and protocolVersion so clients can begin a session.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: MCP lifecycle · Fix skill
initialize advertises capabilities (tools / resources / prompts) SHOULD N/A
Goal: Advertise the capability groups your MCP server implements in the initialize result.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP lifecycle · Fix skill
tools/list returns a tools array with input schemas MUST N/A
Goal: Return tools/list entries with name, description, and a JSON inputSchema.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
resources/list returns at least one resource when advertised SHOULD N/A
Goal: Honor capabilities.resources with a non-empty resources/list result.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP resources · Fix skill
unknown JSON-RPC method returns -32601 SHOULD N/A
Goal: Reject unknown JSON-RPC methods with error -32601 instead of a hang or 500.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: JSON-RPC 2.0 · Fix skill
a non-JSON body draws -32700 (or a typed HTTP 400/415 refusal) SHOULD N/A
Goal: Refuse an unparseable request body with a parse-error envelope or a typed HTTP refusal.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: JSON-RPC 2.0 · Fix skill
a batch carrying a modern-envelope request is rejected -32600 SHOULD N/A
Goal: Refuse JSON array batches that carry modern-era envelopes with -32600.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: JSON-RPC 2.0 · MCP transports (2026-07-28) · Fix skill
tools/call with an unknown tool name returns -32602 SHOULD N/A
Goal: Reject an unknown tool name with -32602 instead of a hang, a 500, or a fake result.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP tools · JSON-RPC 2.0 · Fix skill
a JSON-only Accept is answered without SSE framing SHOULD N/A
Goal: Serve a single application/json response to a client whose Accept names only application/json.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP transports · RFC 9110 section 12.5.1 (Accept) · Fix skill
an unsatisfiable Accept draws a 406 rather than an unasked-for type SHOULD N/A
Goal: Refuse an Accept you cannot satisfy with 406, never a 200 carrying a type the client did not request.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: RFC 9110 section 15.5.7 (406 Not Acceptable) · MCP transports · Fix skill
Modern lane · 2026-07-28
7 not runheader-routed and stateless; no initialize or session
7 checks not run: mcp.stripe.com requires sign-in N/A
anc's public audit holds no sign-in for mcp.stripe.com.
header-routed tools/list (2026-07-28) returns tools without initialize MUST N/A
Goal: Answer a modern header-routed tools/list without requiring an initialize handshake.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP lifecycle (2026-07-28) · MCP tools (2026-07-28) · Fix skill
server/discover answers with server identity on the modern lane SHOULD N/A
Goal: Answer server/discover with supported versions, capabilities, and server identity.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP lifecycle (2026-07-28) · Fix skill
an unknown method on the modern lane returns -32601 SHOULD N/A
Goal: Reject unknown header-routed methods with -32601 on the 2026-07-28 lane.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: JSON-RPC 2.0 · MCP lifecycle (2026-07-28) · Fix skill
_meta missing clientCapabilities is rejected (-32602 or -32600) SHOULD N/A
Goal: Enforce the mandatory clientCapabilities key on every modern request.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: MCP lifecycle (2026-07-28) · Fix skill
an Mcp-Method header disagreeing with the body method draws -32020 SHOULD N/A
Goal: Validate the SEP-2243 header mirror between Mcp-Method and the body method.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: MCP lifecycle (2026-07-28) · Fix skill
an unsupported protocol version is rejected -32022 with data.supported SHOULD N/A
Goal: Refuse unsupported protocol version claims with -32022 and advertise the served revisions.
Result: Not evaluated: mcp.stripe.com requires sign-in (HTTP 401 from https://mcp.stripe.com/)
Resources: MCP lifecycle (2026-07-28) · Fix skill
modern resources/read with an unknown URI returns -32602 SHOULD N/A
Goal: Answer an unknown resource URI with the typed miss code, not a hang or a fake result.
Result: Not evaluated: mcp.stripe.com requires sign-in (https://mcp.stripe.com/)
Resources: MCP resources (2026-07-28) · JSON-RPC 2.0 · Fix skill
In-page tools · WebMCP
browser tools exposed by the site's HTML, not by the MCP server
Root HTML exposes WebMCP browser tools MAY N/A
Evaluated at
stripe.devGoal: Expose page tools to browser agents via WebMCP.
Result: Not implemented, optional (https://stripe.dev/ -> 200 (no WebMCP markers in root HTML))
Resources: WebMCP spec · Fix skill
-
C6
pass
Agent discovery & auth
1 / 1 checks pass
Evaluated at
mcp.stripe.com, declared by stripe.dev's server card (transport.url)OAuth/OIDC discovery metadata published MAY N/A
Evaluated at
stripe.devGoal: Publish OAuth/OIDC discovery metadata if agents authenticate to your service.
Result: Not implemented, optional (https://stripe.dev/.well-known/openid-configuration -> 404 (status 404 not in [200]))
A2A Agent Card published for agent-to-agent discovery MAY N/A
Evaluated at
stripe.devGoal: Publish an A2A Agent Card for agent-to-agent discovery.
Result: Not implemented, optional (https://stripe.dev/.well-known/agent-card.json -> 404 (status 404 not in [200]))
Resources: A2A protocol · Fix skill
/.well-known/ai-catalog.json published (ARD) MAY N/A
Evaluated at
stripe.devGoal: Publish an Agentic Resource Discovery catalog so agents can enumerate your AI artifacts.
Result: Not implemented, optional (https://stripe.dev/.well-known/ai-catalog.json -> 404 (status 404 not in [200]))
Resources: AI Catalog · Fix skill
Agent-skills discovery index published MAY N/A
Evaluated at
stripe.devGoal: Publish an agent-skills discovery index so agents can enumerate your skills.
Result: Not implemented, optional (https://stripe.dev/.well-known/agent-skills/index.json -> 404 (status 404 not in [200]))
Resources: Agent Skills Discovery · Fix skill
Agent auth/registration metadata doc published MAY N/A
Evaluated at
stripe.devGoal: Publish an auth.md telling agents how to obtain credentials.
Result: Not implemented, optional (https://stripe.dev/.well-known/auth.md -> 404)
Resources: anc.dev example · Fix skill
Scored against registry 6ea67d98418f.
This scorecard reflects the target's public agent-facing surface and the hosts it declares at audit time. Re-audit from the control above to refresh it, or call the audit_website MCP tool.