AgentsReady
Verified deep dive · Commerce

Zomato

Run the agent liveReport a change
3 minTime to key
NoNo-human path
3Human gates
5/10Onboarding score
Manual reviewPartner applicationPhone OTP

Fastest path to a key

  1. No developer API key (public API shut down). Personal agent path: add remote MCP https://mcp-server.zomato.com/mcp in Claude (custom connector or official directory listing), ChatGPT, VS Code or Postman.
  2. Phone OTP
    Client registers via DCR (/register) -> OAuth authorize -> log in to Zomato (phone OTP) -> token.
  3. Tools: restaurant discovery, menus, cart, place order, QR-code payment (user pays via UPI QR).
  4. Manual review
    Custom clients (e.g. Claude Code localhost redirect) are NOT on the redirect-URI allowlist -> must fill 'MCP Developer Access' form (personal use only) and wait for review.
  5. Working API key

Biggest gap

No third-party apps permitted; redirect allowlist breaks DCR for new clients; robots.txt contradicts the llms.txt invitation.

Worth copying

llms.txt written as an operating manual for browser agents with explicit confirm-before-order rule; DCR-enabled remote MCP with one-click VS Code install.

Sources (10) · checked 2026-10-11
11Readiness score / 100
L0 Agent-invisibleBeats 3% of 1,846 companies
Access10/20
Context1/20
Interfaces0/32
Onboarding0/19
Trust0/9

Biggest gains

  1. +12 Remote MCP server for the product. Host a remote MCP server (e.g. mcp.<domain>/mcp, Streamable HTTP) for your core actions.
  2. +10 Agents get the real page, not a bot wall. Serve the homepage to AI user-agents (Claude-User, ChatGPT-User) without a challenge or 403.
  3. +8 llms.txt exists. Publish /llms.txt: a markdown index of your docs at the root or docs host.
All 20 checks
  • FAILAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • PASSContent is server-rendered4
  • FAILllms.txt exists8
  • FAILllms-full.txt exists3
  • FAILDocs available as markdown6
  • FAILSitemap2
  • PASSStructured metadata1
  • FAILPublic developer docs4
  • FAILMachine-readable API spec8
  • FAILRemote MCP server for the product12
  • FAILDocs MCP or searchable docs4
  • FAILSDKs and a CLI4
  • FAILOAuth discovery metadata5
  • FAILAgents can self-register OAuth clients6
  • FAILSelf-serve API keys5
  • FAILFree tier or test mode3
  • FAILAgent manifests4
  • FAILsecurity.txt2
  • FAILPublic status page3

Your fix pack: 18 changes, up to +89 points

Each change is ready to paste, filled in for zomato.com, with a command to check it worked. Or hand the whole list to your coding agent.

A remote MCP server lets Claude, ChatGPT and Cursor act on your product in one click, with no glue code.

Where: https://mcp.zomato.com/mcp (Streamable HTTP)
// npm i @modelcontextprotocol/sdk zod  — minimal remote MCP server (Streamable HTTP, stateless)
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StreamableHTTPServerTransport } from "@modelcontextprotocol/sdk/server/streamableHttp.js";
import express from "express";
import { z } from "zod";

const app = express();
app.use(express.json());

app.post("/mcp", async (req, res) => {
  const server = new McpServer({ name: "zomato.com", version: "1.0.0" });
  // One tool per core job. Clear verbs, typed inputs, small outputs.
  server.tool("create_<thing>", "Create a <thing> for the signed-in user.", { name: z.string() },
    async ({ name }) => {
      const key = req.headers.authorization?.replace("Bearer ", ""); // scoped API key or OAuth token
      const r = await fetch("https://zomato.com/v1/<things>", { method: "POST", headers: { Authorization: `Bearer ${key}` }, body: JSON.stringify({ name }) });
      return { content: [{ type: "text", text: await r.text() }] };
    });
  const transport = new StreamableHTTPServerTransport({ sessionIdGenerator: undefined });
  res.on("close", () => transport.close());
  await server.connect(transport);
  await transport.handleRequest(req, res, req.body);
});
app.listen(3000);
Check it worked:curl -s -X POST https://mcp.zomato.com/mcp -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"t","version":"1"}}}' -i | head -15

Add the badge to your README

AgentsReady badge for zomato.com
[![AgentsReady](https://agentsready.dev/badge/zomato.com)](https://agentsready.dev/c/zomato.com)