Agent readiness · File upload and storage
cloudflare.com
13 of 14 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with. 2 of them could not be measured from where we ask, and those are left out of the denominator rather than counted as failures.
A · Discovery
- PASSAnswers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
- PASSllms.txt publishedllms.txt and llms-full.txt present at https://www.cloudflare.com/llms.txt and https://www.cloudflare.com/llms-full.txt and https://docs.cloudflare.com/llms.txt and https://developers.cloudflare.com/llms-full.txt, and the 12 links we sampled across both files all answer
- PASSDocs readable without JavaScript9,312 characters of text without JS
- PASSOn-demand agents not blockedExplicitly allowed: ChatGPT-User
- N/APaths robots.txt points at answerrobots.txt names no concrete path, only patterns or nothing, so there is no claim to check
- PASSNo punishing crawl delayNo Crawl-delay applies to the agents we check
B · Agent entry
- PARTAgent entry pointOnly service descriptors: https://www.cloudflare.com/.well-known/mcp.json, https://www.cloudflare.com/.well-known/agent.json. No procedure written for a machine.
- PASSOAuth dynamic client registrationregistration_endpoint published, but none of the 2 advertised grants (authorization_code, refresh_token) finishes without a person at a browser
- PASSMCP surfaceLive MCP endpoint at https://mcp.cloudflare.com/mcp, answered 401 with an auth challenge
C · Registration
- UNMEASUREDNo CAPTCHA in the signup HTMLUnmeasurable: the signup form at https://dash.cloudflare.com/sign-up is not in the server HTML, so its gates are not eitherServer-render the form, or tell us the endpoint it posts to, and the gates become visible to us and to an agent.
- UNMEASUREDSignup reachable without a browserUnmeasurable: https://dash.cloudflare.com/sign-up answers 403 to an agent and 403 to a Chrome user-agent, so nothing gets in from here and the difference we test for cannot be seenNothing for you to do here. It becomes measurable from a network your edge admits.
D · Provisioning
- PASSProgrammatic key provisioning2 of 7 provisioning phrases across the 8 documents we read: "account api", "create an api key (or api token, access token, personal access token, service account, auth token, secret key), next to something programmatic"
- PASSFree tier or no-card trial stated in textFree tier or no-card signals at https://www.cloudflare.com/plans/: "$0"
E · Integration
- PASSTyped SDK on the registrycloudflare@7.0.0 ships types, matched from the registry by who publishes it rather than by a link on your site
- PASSMachine-readable API descriptionOpenAPI at https://www.cloudflare.com/openapi.json
Tell me when this changes
The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.
This page is the newest scan we hold for cloudflare.com and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.