SSL / TLS
Valid HTTPS · 401ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
HTTP 401 · 114ms
security.txt
Not found · 62ms
CORS headers
No CORS header (OK if server-to-server only) · 397ms
Security headers
4/5 present (all critical headers set) · 401ms
Response time
415ms avg · 415ms
MCP server
No MCP endpoint found
API endpoints
2 endpoints found
Error handling
Returns 401 for unknown paths · 135ms
x402 compliance
No x402 payment gates found · 415ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 453ms
Documentation
No documentation endpoint
robots.txt AI crawlers
No AI crawler directives (GPTBot, ClaudeBot, etc.) · 535ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
No OpenAPI/Swagger spec found
Privacy / GDPR
No privacy policy or GDPR endpoint
Status / Health
No status or health endpoint
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
DNSSEC active (1 DNSKEY records on api.spotify.com)
CAA Records
1 CAA record(s) found on api.spotify.com
DMARC / SPF
No DMARC or SPF records found
Auth maturity
No authentication detected — open API or check failed
API versioning
/v1
Human oversight
/agent/stop — auth-protected (EU AI Act Art. 14) · 232ms
Terms of Service
No Terms of Service endpoint found
Content-Type
Could not test endpoints
OASF Classification
No OASF or agent service classification found
MCP Transport Security
No MCP endpoint found
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 3x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Warning — 23security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
MCP server needs attentionNo MCP endpoint found
Error handling needs attentionReturns 401 for unknown paths
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
Documentation needs attentionNo documentation endpoint
robots.txt AI crawlers needs attentionNo AI crawler directives (GPTBot, ClaudeBot, etc.)
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attentionNo OpenAPI/Swagger spec found
Privacy / GDPR needs attentionNo privacy policy or GDPR endpoint
Status / Health needs attentionNo status or health endpoint
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DMARC / SPF needs attentionNo DMARC or SPF records found
Auth maturity needs attentionNo authentication detected — open API or check failed
Terms of Service needs attentionNo Terms of Service endpoint found
Content-Type needs attentionCould not test endpoints
OASF Classification needs attentionNo OASF or agent service classification found
MCP Transport Security needs attentionNo MCP endpoint found
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration