agentic‑readiness docs
/
Scan at scale Blog Build one › Run a scan ›

DocsCapabilitiesAPI catalog

API catalog

An index at /.well-known/api-catalog listing the site's APIs and their descriptions.

adoption Early productiontrend ▲ risingchecked once per sitechecks 6verified 2026-10-05
Set up API catalog on your site How to list your APIs at one well-known address, in the linkset format RFC 9727 requires.
Free Publish an API catalog

Why an agent cares

One address tells an agent every API the site offers and where each one is described, instead of guessing paths like /openapi.json. It is an IETF standard, so a catalog in the wrong format or pointing at nothing breaks a rule rather than a preference.

Adoption

Early production. Several independent organisations run it in production, though it is still niche on the open web.

Direction of travel: ▲ rising, as at .

Moved from 4 real catalogs in a 74-site census (May 2026) to 7 among 37 well-known agent-focused sites (October 2026), and Cloudflare's Agent Readiness score now checks for one.

AdopterDepthEvidence
Vercelproductionvercel.com
Supabaseproductionsupabase.com
Hugging Faceproductionhuggingface.co
Cloudflare (developer docs)productiondevelopers.cloudflare.com

What we check

Absence is never a finding. Every check below runs only when this technology is detected, so a site that has not adopted this is not assessed on it and appears in no report. 6 of these 7 can fail it. In Lumar these appear once per site, in the site-wide results of each crawl.
CheckSeverityRaisesOn whose authority
API Catalog Malformed Linksethighconformance, usabilityspecification: Linkset: Media Types and a Link Relation Type for Link Sets
API Catalog No API Linkshighconformance, usabilityspecification: api-catalog: A Well-Known URI and Link Relation to Help Discover APIs
apiCatalog HTTPS Downgrademediumusability, security (CWE-319)Lumar readiness bar
API Catalog Wrong Media Typemediumconformance, usabilityspecification: api-catalog: A Well-Known URI and Link Relation to Help Discover APIs
API Catalog Insecure Linkmediumusability, security (CWE-319)Lumar readiness bar, beyond api-catalog: A Well-Known URI and Link Relation to Help Discover APIs
API Catalog Internal Linkmediumusability, security (CWE-200)specification: api-catalog: A Well-Known URI and Link Relation to Help Discover APIs
API Catalog Missing Profileinformationalnothingspecification: api-catalog: A Well-Known URI and Link Relation to Help Discover APIs

Examples

Both run through the same checks as a live scan: the first passes, the second is flagged.

correctjson
{
  "linkset": [
    {
      "anchor": "https://example.com/.well-known/api-catalog",
      "item": [{ "href": "https://api.example.com/v1" }],
      "service-desc": [{ "href": "https://api.example.com/v1/openapi.json", "type": "application/json" }],
      "service-doc": [{ "href": "https://example.com/docs/api", "type": "text/html" }]
    }
  ]
}
present but wrongjson
{
  "version": 1,
  "linkset": [
    {
      "anchor": "https://example.com/.well-known/api-catalog",
      "item": { "href": "https://api.example.com/v1" }
    }
  ]
}

Specifications

Last re-read against the published documents: .