Let Agents In

Agent readiness · Scheduling and calendar APIs

cal.com

10 of 15 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with. 2 of them could not be measured from where we ask, and those are left out of the denominator rather than counted as failures.

A · Discovery

  • PASS
    Answers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
  • PASS
    llms.txt publishedllms.txt present at https://cal.com/llms.txt and https://docs.cal.com/llms.txt, and the 12 links we sampled across the file all answer
  • PASS
    Docs readable without JavaScript9,385 characters of text without JS, on https://cal.com/docs/api-reference/v2/calendars/save-apple-calendar-credentials rather than on https://cal.com/docs/api-reference/v2/introduction
  • PASS
    On-demand agents not blockedNo on-demand agent is blocked
  • FAIL
    Paths robots.txt points at answerthe one concrete path your robots.txt allows is gone: /api/social/og/image
  • PASS
    No punishing crawl delayNo Crawl-delay applies to the agents we check

B · Agent entry

  • FAIL
    Agent entry pointNone of the 9 known agent entry paths returns a file rather than your page shell
  • PASS
    OAuth dynamic client registrationregistration_endpoint published, but none of the 2 advertised grants (authorization_code, refresh_token) finishes without a person at a browser
  • PASS
    MCP surfaceLive MCP endpoint at https://mcp.cal.com/mcp, answered 401 with an auth challenge

C · Registration

  • UNMEASURED
    No CAPTCHA in the signup HTMLUnmeasurable: the signup form at https://cal.com/signup is not in the server HTML, so its gates are not eitherServer-render the form, or tell us the endpoint it posts to, and the gates become visible to us and to an agent.
  • FAIL
    Signup reachable without a browserhttps://cal.com/signup is reachable, but its form needs JavaScript

D · Provisioning

  • PART
    Programmatic key provisioning1 of 7 provisioning phrases across the 6 documents we read: "a documented path like /v1/api_keys or /v2/access-tokens"
  • UNMEASURED
    Free tier or no-card trial stated in textUnmeasurable: https://cal.com/pricing is larger than we read, so anything we did not find in it is a fact about our cap and not about your tiersNothing for you to do. A smaller pricing page, or one that states its tiers early, makes this measurable.

E · Integration

  • PASS
    Typed SDK on the registry@calcom/embed-core@1.5.3 ships types, matched from the registry by who publishes it rather than by a link on your site
  • PASS
    Machine-readable API descriptionDocs serve markdown to machines, at https://cal.com/docs/api-reference/v2/introduction

Tell me when this changes

The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.

This page is the newest scan we hold for cal.com and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.

Scan a domain yourself