Agent-readiness audit UCP 2026-08-25 17 AI agents

Can AI agents shop your store?

Shoppers now ask ChatGPT, Gemini, Claude and Perplexity what to buy, and Gemini can check out without leaving the chat. Legible reads your store the way they do: no JavaScript, through robots.txt, structured data and commerce protocols. Then it writes the fixes.

Free. Public pages only, about 12 polite requests, no JavaScript executed.

legible / report / hollowoak.example

Sample report · fictional store

Hollow Oak Coffee Roasters

WooCommerce

44 E
  1. 01 Access 63/100
  2. 02 Understanding 77/100
  3. 03 Trust 30/100
  4. 04 Transaction 52/100
  • Fail AI search and shopping agents are allowed robots.txt blocks OAI-SearchBot, Claude-SearchBot and PerplexityBot. These agents decide whether your products appear in AI search answers.
  • Fail UCP business profile No UCP profile at /.well-known/ucp, so agents cannot discover a checkout. Few WooCommerce stores publish one yet.
  • Fail Policy pages are linked No shipping and returns page is linked from the homepage or product page.
Open full report

The shift, in four data points

  1. Sep 2025

    OpenAI and Stripe publish the Agentic Commerce Protocol. ChatGPT starts selling products inside the chat.

  2. Jan 2026

    Google announces the Universal Commerce Protocol. Stores publish a profile at /.well-known/ucp and agents check out through it.

  3. Mar 2026

    OpenAI moves checkout back to merchants' own sites. Being found and read inside ChatGPT now depends on your pages and your feed.

  4. ~99%

    of UCP-verified stores run on Shopify. WooCommerce, Magento and custom stores barely register.

    Source: UCP Checker platform data, Oct 2026

The problem

Your store was built for browsers. Agents read it differently.

A shopper sees a polished product page. An agent sees whatever the server sends before any script runs, filtered through robots.txt and your CDN's bot rules. These are the four failures Legible finds most often.

  1. 01

    A "block AI" plugin also blocks AI search.

    Blocking GPTBot is a choice. Blocking OAI-SearchBot, Claude-SearchBot and PerplexityBot removes your products from the answer, and many block lists include them.

  2. 02

    The product only exists after JavaScript runs.

    Client-rendered product pages reach an AI fetcher as an empty shell. No name, no price, no reason to recommend you.

  3. 03

    The schema says one price, the page says another.

    Sale prices that never reach JSON-LD make agents quote the old price, and Google Merchant Center disapproves listings for the same mismatch.

  4. 04

    No protocol, no checkout.

    Without a UCP profile, an agent can recommend your product and then complete the purchase with a store that is set up to sell.

How it works

Thirty seconds. Fifteen requests. Twenty-five checks.

  1. 1Fetch

    Up to 15 polite requests as LegibleBot: homepage, robots.txt, sitemap, a product page, llms.txt and /.well-known/ucp. Public addresses only, every redirect re-checked.

  2. 2Read

    No browser, no JavaScript. The same raw HTML an AI fetcher gets, parsed into the text and structured data an agent can actually use.

  3. 3Score

    Twenty-five checks in four weighted pillars, one score from 0 to 100. A failure that makes the rest irrelevant, like a bot wall, caps the score.

  4. 4Fix

    Every failing check comes with steps for your platform and a snippet generated from your own pages: robots.txt, llms.txt, JSON-LD, UCP.

Request log · hollowoak.example10/15
  1. 200 / · Homepage (as LegibleBot) 1400ms
  2. 200 / · Homepage (as a browser, for bot-wall comparison) 1400ms
  3. 200 /robots.txt · robots.txt 230ms
  4. 301 / · HTTP to HTTPS redirect probe 110ms
  5. 404 /llms.txt · llms.txt 1000ms
  6. 404 /llms-full.txt · llms-full.txt 1000ms
  7. 404 /.well-known/ucp · UCP business profile 1000ms
  8. 200 /sitemap_index.xml · XML sitemap 660ms
  9. 200 /product-sitemap.xml · Product sitemap 610ms
  10. 200 /product/ethiopia-guji-natural/ · Product page (as LegibleBot) 1740ms

What Legible checks

Four questions every agent asks before it recommends you.

01 30% of score

Access

Can an agent reach your pages at all?

robots.txt rules for 17 named agents, bot walls, sitemaps, speed and size. The difference between blocking a training crawler and blocking a shopper.

  • Homepage answers an agent
  • No bot wall in front of the store
  • AI search and shopping agents are allowed
  • Training crawler policy
  • robots.txt is valid
  • XML sitemap lists your products
  • Fast first byte
  • Lean HTML
  • Pages are not marked noindex
02 30% of score

Understanding

Can it read what you sell without running JavaScript?

What survives without JavaScript: product facts in raw HTML, schema.org Product and Offer completeness, OpenGraph, headings and llms.txt.

  • Product facts are in the raw HTML
  • Complete Product structured data
  • Organization and WebSite schema
  • OpenGraph product preview
  • Canonical URL and language
  • One clear H1 with the product name
  • llms.txt guide for agents
03 20% of score

Trust

Can it verify who you are and what the terms are?

Shipping, returns, privacy and terms pages an agent can follow, HTTPS with HSTS, a verifiable business identity, and prices that agree.

  • HTTPS everywhere, with HSTS
  • Policy pages are linked
  • Business identity is machine-readable
  • Visible price matches structured data
04 20% of score

Transaction

Can it start a purchase through a protocol?

A UCP business profile validated against the spec, catalogue feeds, ACP prerequisites, a no-JS add-to-cart path, and your platform.

  • UCP business profile
  • Machine-readable catalogue
  • Agentic Commerce Protocol readiness (signal)
  • Add-to-cart works without scripts
  • Platform and remediation path

Every weight and threshold is published. Read the methodology.

Agent's-eye view

See the page your customers' agents actually get.

Left: the raw HTML the server sends. Right: the markdown an agent extracts from it. Same product page, no JavaScript. Every report includes this view for your store.

Raw HTML · what the server sent

119 KB
<div id="__next">
<div class="app-loading" aria-busy="true">
</div>
</div>
<noscript>You need to enable JavaScript to run this app.</noscript>
<script>/* 117 KB */</script>
<script type="application/json">/* 503 B */</script>

Agent's-eye view · extracted markdown

~0 tokens

0 words

Without JavaScript this page has no readable text. An agent gets nothing to quote, compare or recommend.

Only structured data survived

  • Product name Ember Stoneware Mug
  • Price EUR 34.00
  • Availability InStock
  • Brand Atlas Ceramics Studio

Atlas Ceramics renders its product page in the browser. The agent receives a loading placeholder and a JSON blob, falls back on a thin JSON-LD block, and never sees the description, stock or shipping terms.

Fixes, not findings

Snippets you can paste, generated from your own site.

Legible does not hand you a generic checklist. It writes the files with your URLs, prices and paths, for the platform it detected.

Hollow Oak · WooCommerceLets AI search and user-triggered agents in, keeps training crawlers out (Hollow Oak blocked them, so that choice is kept), and repeats the private WooCommerce paths that a named group would otherwise lose.

robots.txt (AI agents section) Download
# --- AI agents (generated by Legible) ---
# Before pasting: delete any existing groups for the agents named below.
# Groups for the same agent are merged, so old rules would still apply.

# Search and user-triggered agents: allowed, so products can appear
# in ChatGPT, Claude, Perplexity, Google AI Mode and Copilot answers.
# A named group replaces the * group, so your * rules are repeated here.
User-agent: OAI-SearchBot
User-agent: ChatGPT-User
User-agent: Claude-SearchBot
User-agent: Claude-User
User-agent: PerplexityBot
User-agent: Perplexity-User
User-agent: Googlebot
User-agent: Bingbot
User-agent: Amzn-SearchBot
Allow: /
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Disallow: /cart/
Disallow: /checkout/
Disallow: /my-account/
Disallow: /*?add-to-cart=*

# Training crawlers: your current choice is kept. Blocking them does
# not remove you from AI search.
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: Amazonbot
User-agent: meta-externalagent
User-agent: CCBot
User-agent: Bytespider
Disallow: /

User-agent: Applebot-Extended
Allow: /
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Disallow: /cart/
Disallow: /checkout/
Disallow: /my-account/
Disallow: /*?add-to-cart=*

Sitemap: https://hollowoak.example/sitemap_index.xml

Platforms

WooCommerce first. Every platform covered.

Shopify merchants can switch most of this on. Everyone else has to build agent-readiness on purpose. Legible detects your platform and tells you what that means on your stack.

WooCommerce

Deepest coverage

It runs a large share of independent stores and barely appears in UCP. Legible knows where WordPress stores break for agents:

  • "Block AI" plugins and Cloudflare bot rules that catch search agents along with training crawlers
  • Default Product schema gaps: GTIN, brand, shipping details and return policy
  • Sale prices the theme shows but the JSON-LD, or a cached copy of it, does not
  • The public Store API as a ready-made product feed for agent channels
  • UCP plugins from the WordPress.org directory, and what to verify on staging first
  • Uncached PHP pages that run past agents' timeouts

Shopify

Agentic Storefronts and the UCP profile Shopify publishes for you, robots.txt.liquid edits, and theme schema gaps.

Magento / Adobe Commerce

Robots configuration per store view, structured-data extensions, and what a custom UCP binding involves.

PrestaShop

Microdata-only themes, JSON-LD modules and robots.txt regeneration.

Custom and headless

Server rendering, and SPA fallbacks that answer /llms.txt and /.well-known/ucp with an HTML shell.

Pricing

Start free. Monitor once agents matter to revenue.

Free

One store, whenever you need it

€0

  • All 25 checks, four pillars, one score
  • Agent's-eye view of your product page
  • Fixes generated for your platform
  • Markdown, JSON and print-to-PDF export
  • Shareable report link, kept 90 days
Scan a store

Agency

Early access

For studios and freelancers with client stores

€99/ month

  • Up to 25 client stores, re-scanned monthly
  • White-label PDF reports with your logo
  • Client-ready summaries that explain the fix
  • Bulk scans from a list of URLs
  • Everything in Pro
Request early access

Prices exclude VAT. Pro and Agency are onboarded by hand during early access: request a spot by email and we reply within two working days.

Done for you, by Digital Age

Rather have it fixed than read about it?

Legible is built by Digital Age, a software studio in Zagreb that builds fast WooCommerce stores for EU merchants. We implement the fixes from your report, then re-scan before handover so you see the score move.

  1. Access robots.txt and CDN bot rules that keep AI search in and, if you want, training crawlers out
  2. Understanding complete Product, Organization and policy schema, product facts rendered on the server
  3. Trust shipping, returns and contact pages agents can find, HSTS, prices that agree
  4. Transaction a product feed, llms.txt and a UCP profile, tested on staging first

FAQ

Straight answers.

Something missing? Ask us by email.

Is this SEO with a new name?

No. SEO tools measure rankings and traffic. Legible tests whether software agents can fetch, parse and buy from your store. Crawlability and structured data overlap with SEO; user-triggered agents, bot walls, JavaScript-only rendering and commerce protocols do not.

Should I block GPTBot and other training crawlers?

That is your call, and Legible does not score it. Training crawlers do not decide whether you appear in AI answers. Search agents such as OAI-SearchBot and PerplexityBot, and user-triggered agents such as ChatGPT-User, do. Block the first group if you like; keep the second.

Does llms.txt actually matter?

It is a proposal (llmstxt.org) and no major assistant has confirmed reading it, so it is worth 1 of 16 points in the Understanding pillar. It takes five minutes to publish, so Legible generates one from your own pages.

I'm not on Shopify. Can my store support UCP?

Yes. UCP is an open specification. Several WooCommerce plugins on WordPress.org now publish a profile and checkout endpoints, and custom stores can implement the REST or MCP binding. Legible validates your /.well-known/ucp profile against the published shape (version 2026-08-25).

What about ChatGPT and the Agentic Commerce Protocol?

ACP merchants are onboarded through OpenAI with a product feed (applications at chatgpt.com/merchants), so there is no public file to detect. Since March 2026 the purchase completes on the merchant’s own site. Legible checks the prerequisites it can see: OAI-SearchBot access, product data and a feed source.

Why does Legible not run JavaScript?

Because most AI fetchers do not. Vercel’s analysis of AI crawler traffic (December 2024) found that OpenAI’s and Anthropic’s crawlers download JavaScript files but do not execute them. If a fact only appears after scripts run, assume an agent never sees it.

What does a scan do to my server?

About 10 to 15 GET requests with the user agent LegibleBot/1.0: the homepage (twice, once as a browser, to detect bot walls), robots.txt, the sitemap, one product page, llms.txt and /.well-known/ucp. No more than two run at once, each has an 8-second timeout and a 2.5 MB cap. Private and internal addresses are refused.

What do you store?

The findings, the request log and a short excerpt of one product page, so your report link keeps working. Reports expire after 90 days in production. Nothing is shared or sold.

Find out what agents see. It takes thirty seconds.