Can an AI agent get your API key?
Readiness checkers tell you whether agents can read your site. We send one to get a key: watch it search your docs, hit every human gate on the way, and time how long it takes.
Fastest to a key
We traced the shortest path from no account to a working credential for 64 platforms, and logged every point where a human has to step in. The leaders hand agents a sandbox key without an account and let a person claim it later.
| Platform | Time to key | Gates |
|---|---|---|
| Fastest | ||
| CloudflareDevtools | 1 min | No human needed |
| NeonDevtools | 1 min | No human needed |
| WorkOSObservability & auth | 1 min | No human needed |
| StripePayments | 2 min | No human needed |
| PostHogComms & data | 2 min | No human needed |
| NetlifyDevtools | 1 min | No human needed |
| ClerkObservability & auth | 2 min | No human needed |
| Google Gemini APIIndia & cloud | 2 min | Card before first callPhone OTP |
| Slowest | ||
| AirbnbCommerce | n/a | Invite-only API; no MCP |
| WisePayments | days | No self-serve sandbox; no MCP |
| MSG91India & cloud | 15 min | Phone OTP just to view a key |
| PhonePeIndia & cloud | days | No MCP or machine-readable docs |
| FlipkartCommerce | days | Seller KYC; no agent surface |
Two runs, one minute
Probe like an agent
About 60 read-only requests as Claude-User: bot walls, robots.txt, llms.txt, markdown docs, OpenAPI, a live MCP handshake, and OAuth discovery down to dynamic client registration.
Try to get a key
A Claude agent reads your docs and maps the shortest path to a working credential. It never signs up or submits forms. It marks each step an agent can do alone, and each one that needs a person: email, phone OTP, card, KYC, sales.
Fix the gates
You get a fix pack: every missing piece as a file or snippet filled in for your domain (robots.txt, llms.txt, OAuth metadata, an MCP server, auth.md), each with a command to check it worked. Paste them yourself, or copy the whole pack as a prompt for your coding agent.
Built in public
The full gate map, all 64 deep dives with sources, and scores for 2,000 companies are open. Found a gate we missed, or removed one? Open a pull request with evidence and the benchmark updates.