Results for https://www.getbags.app/ LEVEL 5 Scanned just now
Agent-Native
Discoverability
100
4 pass · 0 fail
Content Accessibility
100
1 pass · 0 fail
Bot Access Control
100
3 pass · 0 fail
Discovery
100
7 pass · 0 fail
Commerce
—
2 pass · 0 fail
04 / 04 pass
Discoverability
- fetch GET /robots.txt 200
User-Agent: * Content-Signal: search=yes, ai-input=yes Allow: / Allow: /.well-known/ Disallow: /api/ Disallow: /dashboard/ Sitemap: https://www.getbags.app/sitemap.xml
- conclude robots.txt present with User-agent directive
{"contentType":"text/plain; charset=utf-8"}
- fetch GET /sitemap.xml 200
<?xml version="1.0" encoding="UTF-8"?> <urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <url> <loc>https://www.getbags.app</loc> <lastmod>2026-07-21T18:38:24.847Z</lastmod> <changefreq>weekly</changefreq> <priority>1</priority> </url> <url> <loc>https://www.getbags.app/get-started</loc> <lastmod>2026-07-21T18:38:24.847Z</lastmod> <changefreq>weekly</changefreq> <priority>0.8</priority> </url> <url> <loc>https://www.getbags.app/login</loc> <lastmod>2026-07-21T18:38:24.847Z</lastmod> <…
- parse Valid XML sitemap structure detected
- conclude Sitemap OK at https://www.getbags.app/sitemap.xml
{"url":"https://www.getbags.app/sitemap.xml"}
- fetch GET / 200
- parse Parsed 17 Link entries
- conclude Found agent-useful rels: api-catalog, describedby, describedby, describedby, describedby, describedby, describedby, describedby, describedby, describedby, describedby, service-desc, service-doc, describedby, describedby, status
{"links":[{"rel":"api-catalog","href":"/.well-known/api-catalog"},{"rel":"describedby","href":"/.well-known/agent-skills/index.json"},{"rel":"describedby","href":"/.well-known/mcp/server-card.json"},{"rel":"describedby","href":"/.well-known/agent-card.json"},{"rel":"describedby","href":"/.well-known/oauth-protected-resource"},{"rel":"describedby","href":"/.well-known/openid-configuration"},{"rel":"describedby","href":"/.well-known/oauth-authorization-server"},{"rel":"describedby","href":"/auth.md"},{"rel":"describedby","href":"/merchants.md"},{"rel":"describedby","href":"/.well-known/agents.md"},{"rel":"describedby","href":"/.well-known/http-message-signatures-directory"},{"rel":"service-desc","href":"https://www.getbags.app/api/openapi.json"},{"rel":"service-doc","href":"https://docs.getbags.app"},{"rel":"describedby","href":"https://www.getbags.app/llms.txt"},{"rel":"describedby","href":"https://www.getbags.app/llms-full.txt"},{"rel":"status","href":"https://www.getbags.app/api/health"}]}
- dns AD=true status=0 answers=2
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=2
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- dns AD=true status=0 answers=0
- conclude DNSSEC-validated ServiceMode record(s): _index._agents.getbags.app/SVCB, _mcp._agents.getbags.app/SVCB
{"hits":["_index._agents.getbags.app/SVCB","_mcp._agents.getbags.app/SVCB"]}
01 / 01 pass
Content Accessibility
- fetch GET / 200
--- description: Sell API access to AI agents with x402 pay-per-call and USDC payment links — agents pay per request, no accounts or API keys. title: BAGS Agent | Agentic Commerce for AI Agents image: https://www.getbags.app/og.png --- # Agentic commerce for AI agents BAGS Agent lets API providers charge AI agents per request via x402: an agent calls your endpoint, pays automatically in USDC, and gets the response — no accounts, no API keys, no invoices. - [Get Started](https://www.getbags.ap…
- conclude Content-Type includes text/markdown
{"contentType":"text/markdown; charset=utf-8"}
03 / 03 pass
Bot Access Control
- parse Parsed 1 user-agent group(s)
- conclude Found AI crawler rules or User-agent: * policy
- parse Content-Signal lines: 1
- conclude Found ai-train / search / ai-input directives
{"signals":["search=yes, ai-input=yes"]}
- fetch GET /.well-known/http-message-signatures-directory 200
{"keys":[{"kty":"OKP","crv":"Ed25519","x":"dhufEN25sKfi_aUdmOuyuj-g_AbtPnae7rwbmSD0DKU","kid":"bags-web-bot-auth-1","use":"sig","alg":"EdDSA"}]} - conclude Valid JWKS / message-signatures directory
07 / 08 pass
Discovery
- fetch GET /.well-known/api-catalog 200
{"linkset":[{"anchor":"https://www.getbags.app/api/v1","service-desc":[{"href":"https://www.getbags.app/api/openapi.json","type":"application/json"}],"service-doc":[{"href":"https://docs.getbags.app","type":"text/html"}],"status":[{"href":"https://www.getbags.app/api/health"}],"x402":[{"href":"https://www.getbags.app/api/v1","type":"application/json"}],"x402-resource":[{"href":"https://www.getbags.app/api/agent/link/pl-{paymentLinkId}"}],"describedby":[{"href":"https://www.getbags.app/merchants.… - parse linkset length 1
- conclude Valid linkset catalog
{"linksetCount":1}
- fetch GET /.well-known/openid-configuration 200
{"issuer":"https://www.getbags.app","authorization_endpoint":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/oauth/authorize","token_endpoint":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/oauth/token","userinfo_endpoint":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/oauth/userinfo","jwks_uri":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/.well-known/jwks.json","scopes_supported":["openid","profile","email","phone"],"response_types_supported":["code"],"response_modes_supported":["q… - parse issuer=https://www.getbags.app
- conclude Valid discovery at /.well-known/openid-configuration
{"issuer":"https://www.getbags.app","authorization_endpoint":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/oauth/authorize","token_endpoint":"https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1/oauth/token"}
- fetch GET /.well-known/oauth-protected-resource 200
{"resource":"https://www.getbags.app/api/v1","authorization_servers":["https://www.getbags.app","https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1"],"scopes_supported":["bags:read","bags:write"],"bearer_methods_supported":["header"],"resource_documentation":"https://www.getbags.app/agent-markdown","resource_policy_uri":"https://www.getbags.app/merchant-agreement","resource_tos_uri":"https://www.getbags.app/merchant-agreement"} - parse resource=https://www.getbags.app/api/v1 servers=2
- conclude Valid protected resource metadata
{"resource":"https://www.getbags.app/api/v1","authorization_servers":["https://www.getbags.app","https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1"]}
- fetch GET /auth.md 200
# BAGS auth.md > Agent registration and authentication guide for the BAGS Agent API > (https://www.getbags.app/api/v1). BAGS Agent lets merchants sell API calls to AI > agents via x402 payment links. ## Who this is for AI agents (and the developers operating them) that need authenticated access to the BAGS Agent API: payment links, products, and transactions. Anonymous, read-only surfaces do NOT require registration: - MCP server: `https://www.getbags.app/api/mcp/mcp` (streamable HTTP, no a…
- fetch GET /.well-known/oauth-protected-resource 200
{"resource":"https://www.getbags.app/api/v1","authorization_servers":["https://www.getbags.app","https://dznfhyuvwrlpusdtotct.supabase.co/auth/v1"],"scopes_supported":["bags:read","bags:write"],"beare… - parse agent_auth block found in /.well-known/openid-configuration
- parse authMd=true prm=true agent_auth=true registrationDocs=true
- conclude auth.md + discoverable PRM/agent_auth + registration guidance
{"prmOk":true,"agentAuth":true}
- fetch GET /.well-known/mcp.json 404
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- fetch GET /.well-known/mcp/server-cards.json 404
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- fetch GET /.well-known/mcp/server-card.json 200
{"name":"app.getbags.www","title":"BAGS","description":"BAGS is an Agentic Commerce platform: API providers charge AI agents per request, settlement handled. Tools here let agents preview payment links against the public BAGS API.","version":"0.1.0","websiteUrl":"https://www.getbags.app","repository":{"url":"https://github.com/getbagsapp/agentic-payments","source":"github"},"icons":[{"src":"https://www.getbags.app/baglogo.png","mimeType":"image/png"}],"supportedProtocolVersions":["2025-03-26"],"… - parse Card name=app.getbags.www
- fetch POST /api/mcp/mcp 200
event: message data: {"result":{"protocolVersion":"2025-11-25","capabilities":{"tools":{"listChanged":true}},"serverInfo":{"name":"bags-mcp","version":"0.1.0"}},"jsonrpc":"2.0","id":1} - fetch tools/list 200
event: message data: {"result":{"tools":[{"name":"bags-preview-payment-link","title":"Preview BAGS payment link","description":"Fetch the public metadata for a BAGS payment link by id (uuid). Returns the display name, amount, currency, accepted networks, and merchant info. Use this to preview an agentic x402 endpoint before calling /api/agent/link/pl-{id}.","inputSchema":{"$schema":"http://json-schema.org/draft-07/schema#","type":"object","properties":{"id":{"type":"string","format":"uuid","patt… - conclude MCP card OK (name=app.getbags.www), deepProbe=true
{"name":"app.getbags.www","deepProbeOk":true,"endpoint":"https://www.getbags.app/api/mcp/mcp"}
- conclude Check disabled for this scan
- fetch GET /.well-known/agent-skills/index.json 200
{"$schema":"https://schemas.agentskills.io/discovery/0.2.0/schema.json","skills":[{"name":"bags-x402","type":"skill-md","description":"Charge AI agents for API calls with BAGS — create products and agentic x402 payment links, expose pay-per-call USDC endpoints, and read transactions.","url":"/.well-known/agent-skills/bags-x402/SKILL.md","digest":"sha256:3721116a7c836a5794aa4cf0b58478caaa2863bb8b560dcf17ea6bf9dcdc2d5d"}]} - parse skills array length 1
- conclude Valid skills index at /.well-known/agent-skills/index.json
{"path":"/.well-known/agent-skills/index.json","count":1}
- fetch Launching Browser Rendering session for WebMCP inspection
- parse Captured 1 WebMCP tool registration(s)
- conclude Pass: found 1 tool(s) on navigator.modelContext
{"tools":[{"source":"provideContext","name":"bags-preview-payment-link"}]}
02 / 05 pass
Commerce
- conclude Coinbase Bazaar discovery not queried (skipped in v1 scanner)
- fetch GET / 200
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- fetch GET /api 404
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- fetch GET /api/v1 402
{"x402Version":1,"error":"X-PAYMENT header is required","discovery":true,"accepts":[{"scheme":"exact","network":"base","maxAmountRequired":"10000","resource":"https://www.getbags.app/api/v1","description":"BAGS Agent API index — machine-readable directory of the agentic payment API, MCP server, and x402 payment surface.","mimeType":"application/json","payTo":"0x374cFb844a5C702d637d72a5387fD9EF6B82108C","maxTimeoutSeconds":300,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"name":"… - conclude Valid x402 challenge at /api/v1
{"path":"/api/v1"}
- fetch GET /openapi.json 200
{ "openapi": "3.1.0", "info": { "title": "BAGS Agent API", "version": "v1", "description": "BAGS Agent is an agentic-payments API for x402 payment links, products, and transaction reads.\n\n## Authentication\n\nPublic API endpoints accept either:\n\n- **API key** in the `Authorization: Bearer <key>` header. Keys are prefixed\n `bag_live_…` and generated from the dashboard. Never expose secret keys\n in client code.\n- **Key scope** — standalone agentic merchants use live keys f… - parse x-payment-info present=true
- conclude MPP extensions found
- fetch GET /.well-known/ucp 404
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- conclude HTTP 404
- fetch GET /.well-known/acp.json 404
<!DOCTYPE html><html lang="en" class="__variable_246ccd __variable_35b0e9 __variable_afd4a3 __variable_6d24ac dark" style="color-scheme:dark"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" href="/_next/static/media/22a5144ee8d83bca-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href="/_next/static/media/45d0fdf0988e07ff-s.p.woff2" as="font" crossorigin="" type="font/woff2"/><link rel="preload" href…
- conclude HTTP 404
- conclude Check disabled for this scan
Max level
You’re at Level 5 — Agent-Native.