Machine-Readable Auth
Can an agent authenticate in a way that is bound to it, or only bear a secret? Graded in 0.12.2 (roadmap#97): this credited presence and stopped, so `apiKey` earned the same ten points as OIDC. IETF draft-klrc-aiagent-auth-00 calls static API keys "an antipattern for agent identity — bearer artifacts that are not cryptographically bound, do not convey identity, are typically long-lived and are operationally difficult to rotate". A dimension named Machine-Readable Auth was paying top price for the artifact the field is converging on calling unsuitable. THE FLOOR IS 0.35 AND NOT ZERO, deliberately: a documented API key is still machine-readable auth, and zeroing the 2,209 providers who declare only `apiKey` would measure the market rather than the provider. Read from the refined per-tag OpenAPIs, which already carry `securitySchemes` — no probe and no new artifact. The apis.yml pointer remains a FALLBACK grading `bearer`, so a provider whose specs we have not indexed is not zeroed for our own gap; a pointer cannot name a scheme class. THE ID STAYS `auth_clarity` ON PURPOSE. `auth_scheme_strength` in planned_dimensions describes this change, but the dimension id is POSITIONAL — DIM_ORDER in build_listings.py and DIMENSIONS in the glyph both encode by slot — so renaming it is a coordinated four-place change of the kind roadmap#89 documents. The regrade is the value; the rename is cosmetic and can ride a future glyph release. Same reasoning as the `emits_as` facet aliases.
How it is scored
One signal, read from what the provider publishes, worth 10 points of the 139 in the agent-readiness score.
| Signal the scorer reads | Points |
|---|---|
a served openid-configuration/oauth-authorization-server carrying `issuer` (served), else the securitySchemes class in the provider OpenAPIs — bound (mutualTLS, DPoP, Signature) > negotiable (oauth2 authorizationCode/clientCredentials, openIdConnect) > bearer (http bearer, apiKey) | 10 |
Grades and what each earns
This dimension is graded rather than pass/fail: how the signal was evidenced decides what fraction of the points it earns.
| Grade | Credit | Points | Providers |
|---|---|---|---|
| bound | 1.0× | 10.0 | 14 |
| served | 0.9× | 9.0 | 1,432 |
| negotiable | 0.75× | 7.5 | 740 |
| bearer | 0.35× | 3.5 | 7,784 |
Top providers
The top 500 of 9,970 providers publishing this signal, ranked by credit earned, ties broken by composite.
The other 18 dimensions
github.com/api-evangelist/<provider>, and each check above names the exact artifact it
reads. Publish the artifact, open a pull request, and the next scoring run picks it up — no gatekeeping
and no fee. The full rubric is at apis.io/rating/, and
prioritized profiling
is the fast lane if you would rather have it done for you.
Scored on rubric v0.17.2 across 27,504 providers · lists rebuilt 2026-09-01 · capped at the top 500 per page.