Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make a website usable by AI agents by treating it as a layered system: keep ordinary HTML and APIs reliable, publish crawler preferences, advertise supported agent interfaces, expose narrowly scoped tools, and enforce authentication, authorization, consent, limits, and logging on the server. No declaration file—including robots.txt or an agents manifest—is a security boundary.

How do AI agents access websites?

Agents reach a site through several different paths, and each path has different requirements:

  • Web retrieval: an agent or crawler fetches HTML, follows links, reads a sitemap, and may render JavaScript. Semantic markup, stable URLs, useful headings, and predictable status codes help.
  • API calls: an agent sends structured requests to an API for search, account data, orders, or other operations. The API must authenticate the caller and authorize each action.
  • Model-to-tool connections: an MCP client discovers tools, resources, and prompts exposed by an MCP server, then invokes a selected operation.
  • Agent-to-agent collaboration: an A2A client discovers another agent, negotiates supported interaction modes, and delegates a task that may complete asynchronously.

These layers complement rather than replace one another. A product site might publish documentation and product data as HTML, provide a read-only JSON API, offer an MCP server for controlled actions, and use A2A only for long-running specialist work.

How do I make my website usable by AI agents?

1. Keep the ordinary web surface dependable

Start with the same foundations that help people, search engines, and accessibility tools:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Serve meaningful content in server-rendered or progressively enhanced HTML; do not put the only copy of a page behind an interaction an agent cannot perform.
  • Use semantic headings, lists, tables, labels, alt text, canonical URLs, and descriptive link text.
  • Return accurate HTTP status codes and machine-readable error bodies. Keep URL and field names stable, and document deprecations.
  • Publish an XML sitemap for discoverable public pages and keep it current.
  • Expose an API for operations that need structured input and output instead of asking an agent to scrape a visual form.

Agent infrastructure should augment a working web and API surface. A special file cannot make an inaccessible page understandable, and a protocol cannot make an unsafe endpoint safe.

2. Publish crawler preferences with robots.txt

RFC 9309 standardizes the Robots Exclusion Protocol. A site can request that a user agent avoid paths, but the RFC is explicit: “These rules are not a form of access authorization.” Put no secrets behind a disallow rule. Protect private data and consequential operations with server-side authentication, authorization, and normal application security controls.

A minimal policy might look like this:

User-agent: *
Disallow: /private/
Disallow: /admin/
Sitemap: https://example.com/sitemap.xml

Use separate groups when your objectives differ, and verify the exact syntax and behavior of every crawler you care about. A client that ignores robots.txt can still request a URL, so your firewall, application, and identity layer must handle that case.

3. Distinguish crawler identities and purposes

“AI bot” is not one category. OpenAI’s crawler documentation describes three different identities:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
User agent Documented purpose Policy implication
OAI-SearchBot Surfaces sites in ChatGPT search Allow or disallow based on search visibility goals.
GPTBot Crawls content that may be used to improve foundation models Make a separate training-use decision rather than treating it as search.
ChatGPT-User Visits pages when a person asks a question or interacts with a custom GPT; it is not an automatic web crawler Do not assume a crawler policy covers every user-triggered visit; review the vendor’s current notes.

Map each operator’s published user agents and IP-verification guidance to your actual goals. Re-check those documents because identities, ranges, and product behavior can change. Log requests and investigate unexpected clients instead of relying on a user-agent string as proof of identity.

Should my website publish agents.txt?

Discovery declarations can tell a client which interfaces your organization intends agents to use. The agents.txt project proposes a short, protocol-agnostic root-level declaration and an optional structured agents.json companion. Examples in the project describe MCP and A2A endpoints, authorization modes, skills, and payment protocols. The files advertise interfaces; they do not implement those protocols or grant access.

A separate June 2026 IETF Internet-Draft proposes /.well-known/agents.txt and /.well-known/agents.json for sanctioned capabilities, supported protocols, authentication expectations, and advertised rate limits. It is an Informational Internet-Draft, not a finalized Internet Standard; Internet-Drafts can be replaced or expire. Check the current version before adopting its exact location or fields.

Publish only what you operate

Whichever convention you choose, keep the declaration small and synchronized with live services. Include an endpoint only when it is deployed, documented, monitored, and versioned. State whether authentication is required and where a client can obtain credentials. Remove or mark deprecated endpoints promptly. Treat the manifest as a signpost, not as permission: the service still decides what an authenticated principal may do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is the difference between MCP and A2A?

Question MCP A2A
Interaction target A model or client connecting to tools, prompts, and resources Independent agents collaborating as peers
Typical work Read a database record, call an API, retrieve a resource, or run a narrowly scoped operation Delegate a larger task, negotiate capabilities, exchange context, and receive a result
Execution style Often request/response tool calls Can be asynchronous, with polling, streaming, or push updates declared by the agent
Discovery object Server-provided tools, prompts, and resources An AgentCard describing identity, skills, communication methods, and security requirements

The MCP specification and the A2A specification describe complementary boundaries. One agent can delegate a task over A2A while the receiving agent uses MCP-connected tools to perform the work. Choose based on the boundary you control: expose MCP when a model needs your tools or data; use A2A when another autonomous agent is a peer that must manage a task with you.

How can I safely let an AI agent use my API?

Separate identity from permission

Issue credentials to an application or user, authenticate every request, and authorize the requested resource and action independently. Use short-lived tokens where practical, rotate secrets, scope tokens to the minimum data and operations, and isolate tenants. Never infer permission from a declared skill, an AgentCard, a tool description, an IP address, or a robots.txt entry.

Design tools for least privilege

MCP’s security guidance warns that the protocol can enable “arbitrary data access and code execution paths.” Build tools as constrained application functions, not general-purpose shells:

  • Provide read-only tools separately from write, purchase, deletion, or administrative tools.
  • Define strict schemas, validate every argument on the server, and reject unknown fields.
  • Apply business rules again after validation; never trust model-generated parameters.
  • Require explicit user confirmation for irreversible or high-impact actions.
  • Return only the fields the caller needs, with secrets and internal identifiers redacted.
  • Log principal, tool, arguments after sensitive-value filtering, decision, result, latency, and correlation ID.

The MCP documentation also says implementers remain responsible for consent, privacy, authorization, and data protection; protocol support does not enforce those principles for you. Treat tool annotations and descriptions as untrusted unless they come from a server you trust.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect asynchronous A2A tasks

Authenticate both sides of a delegation, bind callbacks or push notifications to the original task, and make task IDs unguessable. Define expiry, cancellation, retry, and idempotency behavior. Verify the sender of every streamed update and webhook, and keep a complete audit trail from the requesting user through each delegated agent.

Operational controls every agent-facing service needs

  • Rate limits: set per-identity and per-operation quotas, return 429 with a useful retry signal, and protect expensive rendering or model calls with separate budgets.
  • Timeouts and size limits: cap request bodies, pagination, file downloads, tool runtime, and queued task age. Fail closed when a downstream dependency stalls.
  • Observability: record authentication outcomes, authorization decisions, latency, status, cost, and protocol version. Alert on unusual volume, repeated denials, and tool-error spikes.
  • Abuse resistance: validate URLs to prevent server-side request forgery, restrict outbound network destinations, scan uploads, and sandbox code or browser execution.
  • Versioning: publish supported protocol and API versions, maintain compatibility windows, and announce deprecation dates in both documentation and discovery metadata.
  • Human control: provide a way to review, cancel, and revoke agent actions, especially for money movement, account changes, or data export.

What does current interoperability look like?

The 2025 AI Agent Index report, published in 2026, surveyed a sample of 30 agents. Its findings are not a census or a market-share estimate:

Finding in the 30-agent sample Count How to use it
Agents reporting MCP support 20/30 MCP is comparatively common in this sample, but verify the clients your users actually run.
Agents reporting A2A support 6/30 Offer a fallback API or web workflow until your target clients support A2A.
Agents publishing stable user-agent strings and IP ranges 7/30 Do not assume every agent can be reliably identified at the network edge.
Agents explicitly stating robots.txt compliance 6/30 Robots compliance is not uniform; retain server-side controls.

Use actual client support and protocol-version compatibility as acceptance criteria. A technically capable interface is not useful if the agents your audience uses cannot discover or call it.

A practical rollout plan

  1. Inventory surfaces: list public pages, APIs, authenticated operations, data classifications, and irreversible actions.
  2. Fix web and API basics: improve semantic HTML, status codes, schemas, pagination, sitemap coverage, and error messages.
  3. Write crawler policy: decide separately for search, training-related crawling, and user-triggered retrieval; test the resulting robots.txt syntax.
  4. Choose discovery: publish an accurate agents.txt or well-known declaration only for endpoints you operate, and label the June 2026 draft convention as provisional.
  5. Expose the narrowest interface: start with read-only API or MCP tools, then add writes behind confirmation and stronger scopes.
  6. Add controls before launch: authentication, authorization, validation, rate limits, timeouts, audit logs, alerts, and a revocation path.
  7. Test with real clients: exercise happy paths, malformed arguments, expired credentials, replayed requests, denied scopes, cancellation, and downstream failure.
  8. Measure and revise: monitor errors and abuse, update manifests and documentation when interfaces change, and re-check vendor crawler guidance.

Validate what an agent actually sees

A browser check can reveal consent dialogs, newsletter overlays, chat widgets, lazy-loaded content, and responsive-layout failures that an HTML fetch misses. For a do-it-yourself check, run a headless browser in a controlled environment, wait for the page to settle, and save a full-page image:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import { chromium } from 'playwright';

const browser = await chromium.launch();
const page = await browser.newPage({ viewport: { width: 1440, height: 900 } });
await page.goto('https://example.com', { waitUntil: 'networkidle' });
await page.screenshot({ path: 'agent-view.png', fullPage: true });
await browser.close();

Run this in CI against representative pages and authenticated flows without exposing production credentials. Redact screenshots that contain personal or secret data, and make sure your test account cannot trigger real purchases or destructive changes.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server for developers. It is useful when you need a repeatable visual check without maintaining browser infrastructure: it accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.

One request is enough:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for the full option set, including full-page and selector captures, lazy-image loading, dark mode, device presets, retina scale, PDF controls, custom CSS and JavaScript, clicks, waits, blocking rules, headers, cookies, user agents, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage data, and the OpenAPI specification. Parameter names used by other screenshot APIs also work, which can simplify a migration.

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account to test your agent-facing pages.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common failure modes and fixes

An agent receives a blank or incomplete page

Check whether content depends on client-side JavaScript, a consent gate, a blocked third-party script, or lazy loading. Provide server-rendered content or a documented API, and test with a real browser where rendering is unavoidable.

A crawler ignores robots.txt

That is consistent with robots.txt being a request rather than authorization. Add authentication, edge rules, application checks, and monitoring for protected paths; do not attempt to hide credentials in the file.

A tool call is authorized but still dangerous

Authorization may be too broad, arguments may be insufficiently validated, or a downstream action may lack confirmation. Split the tool, narrow scopes, validate server-side, require confirmation, and log the decision.

An A2A task never finishes

Inspect task expiry, callback authentication, queue health, retry policy, and downstream timeouts. Make retries idempotent and expose polling or cancellation when push delivery is unavailable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Clients cannot discover a declared endpoint

Confirm the file location and content match the convention the client implements. Discovery projects and drafts are not universally deployed, so publish conventional API documentation and stable URLs as a fallback.

FAQ

Can I use robots.txt to protect an internal API?

No. Use authentication and server-side authorization; robots.txt cannot protect data or actions.

Is an AgentCard proof that an agent is trustworthy?

No. It describes identity and capabilities for discovery. Verify the peer and enforce permissions independently.

Do I need both MCP and A2A?

Only if your architecture has both boundaries: model-to-tool access and peer-agent delegation. A conventional API may be sufficient for either use case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should a small site implement every protocol?

No. Start with accessible HTML, a well-designed API, and clear crawler policy. Add MCP or A2A when a defined client and workflow justify the operational cost.

Frequently Asked Questions

Can I use robots.txt to protect an internal API?

No. Use authentication and server-side authorization; robots.txt cannot protect data or actions.

Is an AgentCard proof that an agent is trustworthy?

No. It describes identity and capabilities for discovery. Verify the peer and enforce permissions independently.

Do I need both MCP and A2A?

Only if your architecture has both boundaries: model-to-tool access and peer-agent delegation. A conventional API may be sufficient for either use case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should a small site implement every protocol?

No. Start with accessible HTML, a well-designed API, and clear crawler policy. Add MCP or A2A when a defined client and workflow justify the operational cost.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.