AgentsReady
Verified deep dive · Payments

Square

Run the agent liveReport a change
5 minTime to key
NoNo-human path
2Human gates
7/10Onboarding score
Email verificationKYC / business check

Fastest path to a key

  1. squareup.com/signup?v=developers: name, email, password, country, accept terms, business name, application name
  2. Email verification
    verify email (standard Square account)
  3. Developer Console opens the new app automatically
  4. toggle Sandbox, click 'Show' on Sandbox access token, copy
  5. call connect.squareupsandbox.com
  6. production payments: activate account at squareup.com/activation (identity/business + bank)
  7. Working API key

Biggest gap

Remote MCP is production-only; agents testing safely must fall back to a local server with a full-access token.

Worth copying

Granular OAuth scopes published in the MCP protected-resource metadata, so the user approves only what the agent needs.

Sources (6) · checked 2026-10-11
75Readiness score / 100
L3 Agent-operableBeats 92% of 1,846 companies
Access20/20
Context17/20
Interfaces24/32
Onboarding14/19
Trust0/9
llms.txt · root
MCP · https://mcp.squareup.com/mcp

Biggest gains

  1. +8 Machine-readable API spec. Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
  2. +5 Self-serve API keys. Show how to create a key on the first docs page. No sales call.
  3. +4 Agent manifests. Publish an MCP server card (/.well-known/mcp.json) or A2A agent card.
All 20 checks
  • PASSAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • PASSContent is server-rendered4
  • PASSllms.txt exists8
  • FAILllms-full.txt exists3
  • PASSDocs available as markdown6
  • PASSSitemap2
  • PASSStructured metadata1
  • PASSPublic developer docs4
  • FAILMachine-readable API spec8
  • PASSRemote MCP server for the product12
  • PASSDocs MCP or searchable docs4
  • PASSSDKs and a CLI4
  • PASSOAuth discovery metadata5
  • PASSAgents can self-register OAuth clients6
  • FAILSelf-serve API keys5
  • PASSFree tier or test mode3
  • FAILAgent manifests4
  • FAILsecurity.txt2
  • FAILPublic status page3

Your fix pack: 7 changes, up to +25 points

Each change is ready to paste, filled in for squareup.com, with a command to check it worked. Or hand the whole list to your coding agent.

An OpenAPI spec is the contract agents and SDK generators build against. Without it they guess from prose.

Where: https://squareup.com/openapi.json, linked from llms.txt and the API reference
// Serve the spec your API framework already generates (FastAPI: /openapi.json is built in).
// Next.js: app/openapi.json/route.ts
import spec from "@/openapi/openapi.json";
export const GET = () => Response.json(spec, { headers: { "Access-Control-Allow-Origin": "*" } });

// Every operation needs: operationId, summary, description, request/response examples,
// and the auth scheme (components.securitySchemes) so agents know how to send the key.
Check it worked:curl -s https://squareup.com/openapi.json | head -c 200

Add the badge to your README

AgentsReady badge for squareup.com
[![AgentsReady](https://agentsready.dev/badge/squareup.com)](https://agentsready.dev/c/squareup.com)