◎ Discry Score
auth0.com
auth · API
A
0 / 100
DISCOVERY0
COMPREHENSION0
Category leader: 93 (A)
Discry your API →
AUTH · RANK #1 OF 16

Auth0 is Agent-Ready to agents.

Discry independently scored how well an AI agent can discover and understand the Auth0 API from what’s public — not whether it’s usable. Below: every signal we checked, what’s costing the score, and what to change.

Discry your API — freeView the docs ↗

SCORED UNDER RUBRIC 1.2 · A full re-launch under Discry Score 2.5 — a new behavioral instrument, not comparable to these scores — is in progress.

Discovery

45% of score · 90/100
OpenAPI specA machine-readable OpenAPI/Swagger spec agents can parse.Pass
llms.txtAn llms.txt index that points agents to the docs that matter.Pass
llms.txt qualityThe llms.txt is focused, current, and well under the size budget.Partial
llms-full.txtA full-text bundle agents can load in one request.Pass
AGENTS.mdAn AGENTS.md that tells coding agents how to build on the API.Pass
.well-known/mcp.jsonA discoverable MCP manifest at a well-known path.Fail
MCP registryThe API is listed in a public MCP registry.Pass
robots.txt AI directivesrobots.txt allows (or explicitly guides) AI crawlers.Pass
SitemapA sitemap so agents can enumerate the docs surface.Pass

Comprehension

55% of score · 96/100
Task-oriented descriptionsEndpoints described by what they accomplish, not just their shape.Pass
Realistic examplesRunnable, real-world request/response examples.Pass
Multi-step workflowsDocs that chain calls into complete jobs an agent can follow.Pass
Error-recovery guidanceDocumented failure modes and how to recover from them.Pass
Answer-first formatThe answer leads; preamble does not bury it.Pass
Capability boundariesClear limits — what the API can and cannot do.Pass
Naming consistencyConsistent, predictable naming across endpoints.Pass
Heading hierarchyClean heading structure agents can navigate.Pass
Markdown docsDocs available as clean markdown, not JS-rendered HTML only.Pass
Token efficiencyDocs are concise enough to fit an agent context window.Partial

What we found

  • Auth0 is deliberately agent-first: they have an official MCP server, agent-skills repo, AGENTS.md in SDKs, a 'Review Auth0 Agent Experience Score' docs page, and a Documentation Index callout on every page directing agents to llms.txt
  • The Management API documentation is exceptionally comprehensive with detailed pagination guidance (offset vs checkpoint), scope-based auth explanation, and practical curl examples
  • Both llms.txt (405KB) and llms-full.txt (742KB) exist and are API-focused, though both exceed the ideal 50KB threshold for single-context-window consumption
  • Multi-step workflow documentation is best-in-class: the Authorization Code Flow page walks through a 10-step sequence with diagram, then links to implementation guides
  • The only significant gap is .well-known/mcp.json — ironic given Auth0 has an official MCP server but doesn't advertise it via the standard discovery mechanism

What to change

Prioritized by impact on discoverability. You (or your docs platform) deploy these — Discry never touches your API.

  1. 01Add .well-known/mcp.json pointing to the official Auth0 MCP server — trivial win given the server already exists
  2. 02Create a condensed llms.txt under 50KB covering core auth flows (Authorization Code, Client Credentials, Device) with the current comprehensive version becoming llms-full.txt
  3. 03The current llms.txt is already labeled correctly but could benefit from a focused subset for agents that only need core API operations

Execution coverage · INFORMATIONAL, UNSCORED

Whether an agent can actually complete a call and recover from errors is the deeper Audit layer — documented here, but not part of the Discry Score.

oauth2jwtapi_key Error format documented Rate limits documented Pagination documented Idempotency documented

JWT-based Management API access tokens with scope-based permissions. Bearer auth in Authorization header. JSON error responses with structured error codes. Both offset-based and checkpoint-based (cursor) pagination documented with per-plan limits (50 items for public cloud, 100 for private). Checkpoint IDs expire after 24 hours. Rate limits documented per endpoint category. X-Correlation-ID header for request tracking. No idempotency keys mentioned.

See your own Discry Score.

Drop your API docs URL. See what an agent sees — in 60 seconds, free.

Discry your API — free