An API is agent-ready when an AI assistant can use it on a customer's behalf without leaking data, duplicating actions, or doing something nobody asked for. That comes down to twelve checks across four areas: credentials and permissions, reads, writes, and operations. Every item below is verifiable, most of them by the open-source conformance scenario, and none depends on which assistant connects.
Credentials and permissions
- 1. Credentials stay on the server. The assistant never receives an API key or a user token; the server holds them and attaches them to upstream calls.
- 2. Every call is scoped to the caller. Reads and writes answer the question whether this account may touch this record on each call, not only at connection time.
- 3. The MCP endpoint itself is protected once public: bearer tokens or OAuth, so the server knows who is calling.
Reads
- 4. Results are summarised. Fields the user needs, formatted; no raw records, no internal identifiers, no data belonging to other customers.
- 5. Pagination is visible. A cursor is returned, present even when null, and the description tells the assistant that a non-null cursor means the list is incomplete.
- 6. Read tools are annotated
readOnlyHint: true, so clients can treat them as safe.
Writes
- 7. Writes are idempotent. The tool takes a key the assistant generates per request and reuses on retry; a repeated call returns the original result instead of acting twice.
- 8. Consequential actions are guarded. Cancel, delete, pay, change billing: the tool refuses until called with an explicit confirmation, after showing what will happen.
- 9. Write and guarded tools are annotated with
idempotentHintanddestructiveHinttruthfully.
Operations
- 10. Errors say what to do next. Invalid input, not found, conflict and unavailable are distinguished, each with the next step for the assistant.
- 11. A repeatable test exists. A client scenario that lists the tools and exercises reads, pagination, errors, idempotent writes and the guarded action, run on every change. Ours has 25 checks and is open source.
- 12. Someone owns it after launch. Monitoring, secret rotation, and adapting to client changes have a named owner, whether that is your team or a managed host.
The badge
If your server passes all twelve, say so. The badge links back to this checklist so anyone can see what it means. Markdown:
[](https://apitoagents.com/agent-ready)
HTML:
<a href="https://apitoagents.com/agent-ready"><img src="https://apitoagents.com/badges/agent-ready.svg" alt="Agent-ready API" height="24"></a>
It is self-declared and free. We do not verify third-party servers; the value is that the twelve checks are public and specific, so a claim can be questioned.
Frequently asked questions
Is this specific to ChatGPT or Claude?
No. All twelve checks concern the server and the API behind it. The same server serves every MCP client, so passing the list once covers all of them.
Can I check my API without building a server first?
Partly. The free Agent Readiness Audit reads your API documentation and scores readiness across API quality, authentication, tools and testing, which covers the design side of this list before any code exists.
Do the example servers pass?
Items 1, 2 (within the limits of a demo API that has no accounts), 4 through 11 are implemented and tested in all four languages. Item 3 is deliberately absent, since the examples run on localhost and the public demo is a sample; item 12 is ours for the demo.
May I use the badge on a server you did not build?
Yes. It is a self-declaration against a public checklist. Please only use it if your server actually passes all twelve checks.