◎ Discry Score
workos.com
auth · API
B
0 / 100
DISCOVERY0
COMPREHENSION0
Category leader: 93 (A)
Discry your API →
AUTH · RANK #11 OF 16

WorkOS is Good to agents.

Discry independently scored how well an AI agent can discover and understand the WorkOS API from what’s public — not whether it’s usable. Below: every signal we checked, what’s costing the score, and what to change.

Discry your API — freeView the docs ↗

SCORED UNDER RUBRIC 1.2 · A full re-launch under Discry Score 2.5 — a new behavioral instrument, not comparable to these scores — is in progress.

Discovery

45% of score · 83/100
OpenAPI specA machine-readable OpenAPI/Swagger spec agents can parse.Pass
llms.txtAn llms.txt index that points agents to the docs that matter.Pass
llms.txt qualityThe llms.txt is focused, current, and well under the size budget.Partial
llms-full.txtA full-text bundle agents can load in one request.Pass
AGENTS.mdAn AGENTS.md that tells coding agents how to build on the API.Partial
.well-known/mcp.jsonA discoverable MCP manifest at a well-known path.Fail
MCP registryThe API is listed in a public MCP registry.Pass
robots.txt AI directivesrobots.txt allows (or explicitly guides) AI crawlers.Pass
SitemapA sitemap so agents can enumerate the docs surface.Pass

Comprehension

55% of score · 84/100
Task-oriented descriptionsEndpoints described by what they accomplish, not just their shape.Pass
Realistic examplesRunnable, real-world request/response examples.Partial
Multi-step workflowsDocs that chain calls into complete jobs an agent can follow.Pass
Error-recovery guidanceDocumented failure modes and how to recover from them.Partial
Answer-first formatThe answer leads; preamble does not bury it.Pass
Capability boundariesClear limits — what the API can and cannot do.Pass
Naming consistencyConsistent, predictable naming across endpoints.Pass
Heading hierarchyClean heading structure agents can navigate.Pass
Markdown docsDocs available as clean markdown, not JS-rendered HTML only.Pass
Token efficiencyDocs are concise enough to fit an agent context window.Partial

What we found

  • WorkOS has excellent agent-discovery infrastructure: llms.txt (65KB), llms-full.txt (1.6MB), public OpenAPI spec on GitHub, and presence across all three major MCP registries
  • The docs site is heavily JavaScript-rendered, making direct scraping difficult — but the llms.txt files fully compensate by providing clean markdown for agent consumption
  • WorkOS publishes a skills repo (workos/skills) for coding agents with auth implementation guidance, showing deliberate investment in the agent developer experience
  • Rate limits are documented per endpoint category with specific numbers, enabling agents to implement proactive throttling — but error recovery guidance is thin beyond listing status codes
  • The llms.txt at 65KB slightly exceeds the 50KB ideal but is well-organized with clear product descriptions and structured sections

What to change

Prioritized by impact on discoverability. You (or your docs platform) deploy these — Discry never touches your API.

  1. 01Add .well-known/mcp.json advertising available MCP server capabilities
  2. 02Enhance error documentation with actionable recovery steps (e.g., what to do on 401, how to handle connection configuration errors) — current guidance is minimal
  3. 03Trim llms.txt to under 50KB by moving detailed glossary/configuration content to llms-full.txt
  4. 04Add AGENTS.md to primary workos/workos-node or workos/authkit-nextjs repos for coding agent context
  5. 05Consider server-side rendering for docs pages to improve scrapability for agents that don't use llms.txt

Execution coverage · INFORMATIONAL, UNSCORED

Whether an agent can actually complete a call and recover from errors is the deeper Audit layer — documented here, but not part of the Discry Score.

api_keyoauth2jwt Error format documented Rate limits documented Pagination documented Idempotency documented

API key authentication via Bearer token. Standard HTTP error codes (200, 400, 401, 403, 404, 429, 500) documented. Rate limits documented per endpoint: 6,000 requests per 60 seconds per IP (general), with specific limits for SSO and user management endpoints. Cursor-based pagination documented. No idempotency keys mentioned.

See your own Discry Score.

Drop your API docs URL. See what an agent sees — in 60 seconds, free.

Discry your API — free