Agent readiness · Authentication as a service
auth0.com
14 of 16 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with.
A · Discovery
- PASSAnswers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
- PASSllms.txt publishedllms.txt and llms-full.txt present at https://auth0.com/llms.txt and https://auth0.com/llms-full.txt and https://auth0.com/docs/llms.txt, and the 12 links we sampled across both files all answer
- PASSDocs readable without JavaScript10,674 characters of text without JS, on https://auth0.com/docs/api/management/v2/clients/post-credentials rather than on https://auth0.com/docs
- PASSOn-demand agents not blockedNo on-demand agent is blocked
- N/APaths robots.txt points at answerrobots.txt names no concrete path, only patterns or nothing, so there is no claim to check
- PASSNo punishing crawl delayNo Crawl-delay applies to the agents we check
B · Agent entry
- FAILAgent entry pointNone of the 9 known agent entry paths returns a file rather than your page shell
- PASSOAuth dynamic client registrationregistration_endpoint published, and client_credentials is among the 13 advertised grants, so an unattended agent has a documented path to a token
- PASSMCP surfaceLive MCP endpoint at https://mcp.auth0.com/v1/mcp, answered 401 with an auth challenge
C · Registration
- PASSNo CAPTCHA in the signup HTMLNo CAPTCHA vendor in the server HTML. A widget mounted later by JavaScript would not show here.
- PASSSignup reachable without a browserForm renders in server HTML at https://auth0.com/signup?place=header&type=button&text=sign%20up
D · Provisioning
- PASSProgrammatic key provisioning3 of 7 provisioning phrases across the 7 documents we read: "management api", "account api", "service account"
- PASSFree tier or no-card trial stated in textFree tier or no-card signals at https://auth0.com/pricing/: "No credit card"
E · Integration
- PASSTyped SDK on the registryauth0@6.2.0 ships types, matched from the registry by who publishes it rather than by a link on your site
- PASSMachine-readable API descriptionDocs serve markdown to machines, at https://auth0.com/docs
Tell me when this changes
The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.
This page is the newest scan we hold for auth0.com and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.