cortico.health — Cortico is the healthcare connection platform: access to care and records for every patient, plus scheduling, reminders, and messaging built into your EMR.
Verdict: Partially — an AI agent can use cortico.health, but activate is blocked — An SMS code is required at signup.
- DiscoverEasy
- ActivateBlocked
- OperateNot yet probedgated by Activate
- ManageNot yet probedgated by Activate
Capability parity
Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage. A row marked “Not yet probed” means no probe has tried that capability yet — a different ledger from the “unassessed” properties under Findings, where no probe tier capable of catching that interrupt has run.
Discover
Can an agent find and read it, no account?
- Be found by a retrieval agentEasy
Retrieval access present.
Evidence
- Path tried
- robots.txt / sitemap / discovery headers
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
sitemap_xml
- Read what it does and how to use itEasy
Machine-readable docs present.
Evidence
- Path tried
- llms.txt / AGENTS.md / schema.org / docs
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
llms_txt, agents_md, schema_org_jsonld, content_signals
- Read pricing & limits without loginEasy
Public pricing or limits are visible without login.
Evidence
- Path tried
- homepage links / pricing / plans
- Where it stalled
- completed
- Evidence tier
- Tier 0 (passive scan)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
pricing_public
Activate
Can an agent sign up and walk away with the keys it needs?
Assessment incomplete - not yet probed: Obtain an API / MCP access credential; Obtain a management / admin key.
- Create an account self-serveBlocked
An SMS code is required at signup.
SMS / phone OTP verification blocks this.
Evidence
- Path tried
- signup flow
- Where it stalled
- verification step
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- SMS / phone OTP verificationAccount verification (KYC / OTP)Signup form collects a phone/SMS number — indicates SMS/phone verification during onboarding.
- Obtain an API / MCP access credentialNot yet probed
No self-serve credential signal detected - key issuance not yet probed.
- Obtain a management / admin keyNot yet probed
No scoped or administrative key path was confirmed after activation.
- Accept the terms without a bot-banEasy
No bot-prohibition signal found.
Evidence
- Path tried
- ToS / policy scan
- Where it stalled
- completed
- Evidence tier
- Tier 0 (passive scan)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
Operate
Can an agent do the service's actual jobs — call, transact, pay?
No probe has attempted this stage yet: Call the primary service over MCP / API; Pay via an agent rail (x402 / ACP / AP2).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Call the primary service over MCP / APINot yet probed
No machine interface found by passive checks, and no live Tier-2 call attempted.
Gated by Activate — the credential this needs isn't issued unattended.
- Complete a transaction / checkoutNot applicable
Integrated tool — the API call is the transaction, no separate checkout.
Gated by Activate — the credential this needs isn't issued unattended.
- Pay via an agent rail (x402 / ACP / AP2)Not yet probed
No agent-payment metadata detected - payment rails not yet probed.
Gated by Activate — the credential this needs isn't issued unattended.
Manage
Can an agent administer the account and provision resources?
No probe has attempted this stage yet: Provision / scale / tear down a service; Change account details / set budget / rotate keys; View usage & billing; Cancel / export / delete (offboard).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Provision / scale / tear down a serviceNot yet probed
Not probed - provisioning is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- Change account details / set budget / rotate keysNot yet probed
Not probed - account admin is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- View usage & billingNot yet probed
Authenticated usage and billing access was not confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
- Cancel / export / delete (offboard)Not yet probed
No self-serve cancellation, export, or deletion path was confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
Findings
How scoring works →Interrupt tier: Moderate-Interrupt — derived from 2 findings; interrupt score 67 / 100 — the badge-driving metric. (range 36–86 · 8 unassessed)
Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.
Property coverage
A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.
| Property | Stage | State | Evidence | Required |
|---|---|---|---|---|
| SMS / phone OTP verification | activate | failed | Active finding — itemized in the penalty matrix below. Tier 1 assesses this property. | no |
| No Machine Interface | operate | failed | Active finding — itemized in the penalty matrix below. Tier 1 assesses this property. | yes |
| SSO-only signup, no API-key issuance | activate | partial | Some coverage exists, but the available evidence is incomplete. Tier 1 assesses this property. | no |
| Mandatory phone verification call | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Mailed physical code (postal) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| “Contact sales” wall (no self-serve path) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Manual approval queue | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Rate-limit-triggered manual review | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| One-time account / payment-method provisioning | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Identity / KYC verification | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Crypto wallet / key-custody setup | operate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| CAPTCHA / bot-challenge | activate | success | None found — checked at Tier 0 (passive scan) + Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Email OTP verification | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| ToS clause banning automated/bot access | discover | success | None found — checked at Tier 0 (passive scan) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Mandatory redirect to vendor’s own site | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| Interrupt found | Base weight | × Timing | × Hardness | × Evidence | = Penalty |
|---|---|---|---|---|---|
| Starting score | 100 | ||||
| No Machine InterfaceoperateNeither an MCP server nor a usable API machine interface was found after Tier 0 and Tier 1 candidate checks. | 9 | ×1one-time setup | ×2.5hard | ×0.8Tier 1 (unauth probe)inferred | −9 |
| SMS / phone OTP verificationAccount verification (KYC / OTP)Signup form collects a phone/SMS number — indicates SMS/phone verification during onboarding. | 5 | ×1one-time setup | ×2.5hard | ×0.8Tier 1 (unauth probe)inferred | −5 |
| Total penalty | −14 | ||||
| Full unknown tax 105 — capped at 25 (point score uses 50% of the capped value) | −105 | ||||
| Evidence-graded tax (successes not live-verified by a Tier 2 probe) 123.4 — capped at 25 (point score uses 25% of the capped value) | −123.4 | ||||
| Raw score = 100 − 14 = 86 Point score = 86 − 50% × 25 − 25% × 25 = 67.3 → 67 | 67 | ||||
inferred = detected from passive signals, not a directly observed interrupt — penalized at half weight
What would make this Easy
One concrete change per blocker found. These are the diffs between this listing's current parity and an unattended agent path.
- Activate — SMS / phone OTP verificationAllow email-only verification, or offer SSO alongside an API-key path.
How we scored this
- Confidence: Provisional (0.55) — Based on Tier 0/1 evidence only (passive checks, no live transaction attempt) — treat the number as a triage signal, not a verified outcome.
- Machine-Readability sub-score: 63 / 100 (a separate integration-ease signal — it never enters the Interrupt Score or badge).
- Some capability stages are not yet probed — shown plainly in the spine above, never as a pass.
- Rubric, tiers, confidence model, and badge thresholds →
Machine-readability checks 63 / 100
Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →
- Unauthenticated API error is structured JSONplausibleNot provided
- Unauthenticated API returns auth guidance (401/403 or documented)plausibleNot provided
- API exposes rate-limit headersplausibleNot provided
- API key obtainable without human interactionplausibleNot checked — no OpenAPI spec found; self-serve API-key path indeterminate from Tier 1
- llms.txtemergingFound — cortico.health/llms.txt (4.3 KB, 27 links)
- llms-full.txtemergingNot provided
- AGENTS.mdemergingFound — cortico.health/AGENTS.md
- A2A agent cardemergingNot provided
- MCP server (well-known or official registry)plausibleNot provided
- OpenAPI/Swagger specplausibleNot provided
- Rate-limit headersplausibleNot provided
- Structured JSON error responsesplausibleFound — cortico.health/ (HTTP 404 JSON error body)
- OAuth authorization-server metadata (RFC 8414)provenNot provided
- API catalog (RFC 9727) (emerging)emergingNot provided
- Agent-payment discovery (x402 / UCP) (emerging)emergingNot provided
- Lean HTML transfer sizeplausible146 KB raw HTML (threshold 488 KB)
- Manageable DOM sizeplausible1367 DOM nodes (threshold 1500)
- High content-to-markup densityplausible5.2% text/HTML (7791 chars in 146 KB, threshold 2%)
- Content readable without JS executionprovenraw HTML holds 111% of rendered text (7791 vs 7009 chars; threshold 40%)
- Clean-content alternate (RSS/Atom/feed/markdown)plausibleNot provided
- Serves markdown on Accept: text/markdownplausibleNot provided
- Interactive elements are semanticplausible163/163 semantic (100%); 0 div/span click targets
- Form fields have accessible namesplausible8/8 named (100%)
- Inputs carry autocomplete hintsplausible4/8 with autocomplete (50%)
- WebMCP tools (modelContext API)emergingNot provided
- AI retrieval/search fetchers allowed (robots.txt)provenNot provided
- Sitemap (indexability)plausibleFound — cortico.health/sitemap_index.xml
- schema.org JSON-LD in raw HTMLplausible2 valid JSON-LD block(s) in raw (pre-JS) HTML
- Content-Signal directives (robots.txt)emergingsearch=yes, ai-input=yes, ai-train=yes
- Web Bot Auth key directory (emerging)emergingNot provided
- Discovery Link headers on homepage (emerging)emergingNot provided
- Pricing visible without loginFound — cortico.health/pricing/
- robots.txt AI-crawler accessplausibleNot provided
Evidence & history
Last probed 2026-09-07 01:51 UTC. The raw JSON is the archival record.
| Date | Score | Badge | Rubric version |
|---|---|---|---|
| 2026-09-07 01:51 UTC | 67 | Moderate-Interrupt (current) | rubric v2026.4 |
| 2026-09-06 20:40 UTC | 67 | Moderate-Interrupt | rubric v2026.4 |
| 2026-09-06 20:40 UTC | 81 | Low-Interrupt | rubric v2026.4 |
Alternatives in Other
Other Other tools in the same mode (integrated), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.