Let Agents In

Agent readiness · Managed databases

xata.io

7 of 15 measurable points under formula 9.2, measured on 2026-08-12. 15 checks exist; each is one HTTP request with a published rule, so every sentence below can be rerun and argued with. 1 of them could not be measured from where we ask, and those are left out of the denominator rather than counted as failures.

A · Discovery

  • PASS
    Answers an agent user-agentAnswered 200 to LetAgentsIn/1.0 (+https://letagentsin.com/methodology)
  • PASS
    llms.txt publishedllms.txt and llms-full.txt present at https://xata.io/llms.txt and https://xata.io/llms-full.txt and https://docs.xata.io/llms.txt, and the 12 links we sampled across both files all answer
  • PASS
    Docs readable without JavaScript12,229 characters of text without JS, on https://xata.io/docs/api-reference/api-keys/create-an-organization-api-key rather than on https://xata.io/docs/overview
  • PASS
    On-demand agents not blockedNo on-demand agent is blocked
  • N/A
    Paths robots.txt points at answerrobots.txt names no concrete path, only patterns or nothing, so there is no claim to check
  • PASS
    No punishing crawl delayNo Crawl-delay applies to the agents we check

B · Agent entry

  • FAIL
    Agent entry pointNone of the 9 known agent entry paths returns a file rather than your page shell
  • FAIL
    OAuth dynamic client registrationNo OAuth metadata on any of the 9 hosts probed, including the usual auth and api subdomains
  • FAIL
    MCP surfaceMCP mentioned 1x in your own files, but nothing answered at mcp.xata.io, mcp.xata.io/mcp, mcp.xata.io/v1/mcp, api.xata.io/mcp, /mcp or /api/mcp

C · Registration

  • UNMEASURED
    No CAPTCHA in the signup HTMLUnmeasurable: the signup form at https://console.xata.io/signup is not in the server HTML, so its gates are not eitherServer-render the form, or tell us the endpoint it posts to, and the gates become visible to us and to an agent.
  • FAIL
    Signup reachable without a browserhttps://console.xata.io/signup is reachable, but its form needs JavaScript

D · Provisioning

  • PART
    Programmatic key provisioning1 of 7 provisioning phrases across the 7 documents we read: "create an api key (or api token, access token, personal access token, service account, auth token, secret key), next to something programmatic"
  • FAIL
    Free tier or no-card trial stated in textThe only free-tier wording at https://xata.io/pricing is a question the page asks, "Is there a free tier?", and the answer to it is not in the HTML we were servedServe the answer to that question in the HTML, or state the tier in the pricing table, and this becomes a pass.

E · Integration

  • FAIL
    Typed SDK on the registry@xata.io/api ships without bundled types, matched from the registry by who publishes it rather than by a link on your site
  • PASS
    Machine-readable API descriptionDocs serve markdown to machines, at https://xata.io/docs/overview

Tell me when this changes

The failures here are the kind nobody notices. An edge rule that starts refusing agents changes nothing a person sees in a browser, so the first sign is usually an integration that quietly stopped working. We rescan weekly and write only when a verdict moves.

This page is the newest scan we hold for xata.io and changes when we rescan. It is not a judgement of the product: we measure whether an unattended run can get through, not whether the thing is any good. The whole corpus is published as JSON and CSV.

Scan a domain yourself