Crossmint
crossmint.com · Agent-Commerce Infrastructure modeIntegrated
Last probed 2026-10-07 04:17 UTC · Provisional
Crossmint — Agent payments/wallets/checkout API spanning cards + stablecoins across 1B+ SKUs.
Verdict: Partially — an AI agent can use Crossmint, but activate is blocked — An SMS code is required at signup.
- DiscoverIncomplete
- ActivateBlocked
- OperateIncompletegated by Activate
- ManageNot yet probedgated by Activate
Capability parity
Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage. A row marked “Not yet probed” means no probe has tried that capability yet — a different ledger from the “unassessed” properties under Findings, where no probe tier capable of catching that interrupt has run.
Discover
Can an agent find and read it, no account?
Assessment incomplete - not yet probed: Read pricing & limits without login.
- Be found by a retrieval agentEasy
Retrieval access present.
Evidence
- Path tried
- robots.txt / sitemap / discovery headers
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
retrieval_bot_access, sitemap_xml
- Read what it does and how to use itEasy
Machine-readable docs present.
Evidence
- Path tried
- llms.txt / AGENTS.md / schema.org / docs
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
llms_txt, llms_full_txt, agent_card, schema_org_jsonld
- Read pricing & limits without loginNot yet probed
Public pricing was not confirmed - the page was absent, gated, or unreadable.
Activate
Can an agent sign up and walk away with the keys it needs?
Assessment incomplete - not yet probed: Obtain a management / admin key.
- Create an account self-serveBlocked
An SMS code is required at signup.
SMS / phone OTP verification blocks this.
Evidence
- Path tried
- signup flow
- Where it stalled
- verification step
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- SMS / phone OTP verificationAccount verification (KYC / OTP)Signup form collects a phone/SMS number — indicates SMS/phone verification during onboarding.
- Obtain an API / MCP access credentialEasy
Self-serve credential path detected.
Evidence
- Path tried
- docs → key issuance
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
api_key_self_serve
- Obtain a management / admin keyNot yet probed
No scoped or administrative key path was confirmed after activation.
- Accept the terms without a bot-banEasy
No bot-prohibition signal found.
Evidence
- Path tried
- ToS / policy scan
- Where it stalled
- completed
- Evidence tier
- Tier 0 (passive scan)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
Operate
Can an agent do the service's actual jobs — call, transact, pay?
Assessment incomplete - not yet probed: Pay via an agent rail (x402 / ACP / AP2).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Call the primary service over MCP / APIEasy
Machine interface present — evidence-only, not live-verified.
Gated by Activate — the credential this needs isn't issued unattended.
Evidence
- Path tried
- API / MCP / browser
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
openapi_spec
- Complete a transaction / checkoutNot applicable
Integrated tool — the API call is the transaction, no separate checkout.
Gated by Activate — the credential this needs isn't issued unattended.
- Pay via an agent rail (x402 / ACP / AP2)Not yet probed
No agent-payment metadata detected - payment rails not yet probed.
Gated by Activate — the credential this needs isn't issued unattended.
Manage
Can an agent administer the account and provision resources?
No probe has attempted this stage yet: Provision / scale / tear down a service; Change account details / set budget / rotate keys; View usage & billing; Cancel / export / delete (offboard).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Provision / scale / tear down a serviceNot yet probed
Not probed - provisioning is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- Change account details / set budget / rotate keysNot yet probed
Not probed - account admin is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- View usage & billingNot yet probed
Authenticated usage and billing access was not confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
- Cancel / export / delete (offboard)Not yet probed
No self-serve cancellation, export, or deletion path was confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
Findings
How scoring works →Interrupt tier: Moderate-Interrupt — derived from 1 finding; interrupt score 76 / 100 — the badge-driving metric. (range 45–95 · 9 unassessed)
Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.
Property coverage
A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.
| Property | Stage | State | Evidence | Required |
|---|---|---|---|---|
| SMS / phone OTP verification | activate | failed | Active finding — itemized in the penalty matrix below. Tier 1 assesses this property. | no |
| CAPTCHA / bot-challenge | activate | unassessed | Tier 0 (passive scan) + Tier 1 (unauth probe) ran but did not gather enough evidence to claim clean. Tier 0 assesses this property. | no |
| Mandatory phone verification call | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Mailed physical code (postal) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| “Contact sales” wall (no self-serve path) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Manual approval queue | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Rate-limit-triggered manual review | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| One-time account / payment-method provisioning | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Identity / KYC verification | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Crypto wallet / key-custody setup | operate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Email OTP verification | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| ToS clause banning automated/bot access | discover | success | None found — checked at Tier 0 (passive scan) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Mandatory redirect to vendor’s own site | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| SSO-only signup, no API-key issuance | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| No Machine Interface | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | yes |
| Interrupt found | Base weight | × Timing | × Hardness | × Evidence | = Penalty |
|---|---|---|---|---|---|
| Starting score | 100 | ||||
| SMS / phone OTP verificationAccount verification (KYC / OTP)Signup form collects a phone/SMS number — indicates SMS/phone verification during onboarding. | 5 | ×1one-time setup | ×2.5hard | ×0.8Tier 1 (unauth probe)inferred | −5 |
| Total penalty | −5 | ||||
| Full unknown tax 104 — capped at 25 (point score uses 50% of the capped value) | −104 | ||||
| Evidence-graded tax (successes not live-verified by a Tier 2 probe) 142.4 — capped at 25 (point score uses 25% of the capped value) | −142.4 | ||||
| Raw score = 100 − 5 = 95 Point score = 95 − 50% × 25 − 25% × 25 = 76.3 → 76 | 76 | ||||
inferred = detected from passive signals, not a directly observed interrupt — penalized at half weight
What would make this Easy
One concrete change per blocker found. These are the diffs between this listing's current parity and an unattended agent path.
- Activate — SMS / phone OTP verificationAllow email-only verification, or offer SSO alongside an API-key path.
How we scored this
- Confidence: Provisional (0.55) — Based on Tier 0/1 evidence only (passive checks, no live transaction attempt) — treat the number as a triage signal, not a verified outcome.
- Machine-Readability sub-score: 62 / 100 (a separate integration-ease signal — it never enters the Interrupt Score or badge).
- Some capability stages are not yet probed — shown plainly in the spine above, never as a pass.
- Rubric, tiers, confidence model, and badge thresholds →
Machine-readability checks 62 / 100
Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →
- Unauthenticated API error is structured JSONplausibleFound — api.crossmint.com/ (HTTP 421)
- Unauthenticated API returns auth guidance (401/403 or documented)plausibleNot provided
- API exposes rate-limit headersplausibleNot provided
- API key obtainable without human interactionplausibleOpenAPI spec published and signup is not SSO-only
- llms.txtemergingFound — www.crossmint.com/llms.txt (10.1 KB, 69 links)
- llms-full.txtemergingFound — docs.crossmint.com/llms-full.txt (1024.0 KB, 618 links)
- AGENTS.mdemergingNot provided
- A2A agent cardemergingFound — docs.crossmint.com/.well-known/agent-card.json
- MCP server (well-known or official registry)plausibleNot provided
- OpenAPI/Swagger specplausibleFound — www.crossmint.com/openapi.yaml
- Rate-limit headersplausibleNot provided
- Structured JSON error responsesplausibleNot provided
- OAuth authorization-server metadata (RFC 8414)provenNot provided
- API catalog (RFC 9727) (emerging)emergingNot provided
- Agent-payment discovery (x402 / UCP) (emerging)emergingNot provided
- Lean HTML transfer sizeplausible126 KB raw HTML (threshold 488 KB)
- Manageable DOM sizeplausibleNot checked — page did not render
- High content-to-markup densityplausible6.5% text/HTML (8425 chars in 126 KB, threshold 2%)
- Content readable without JS executionprovenNot checked — raw and/or rendered text unavailable
- Clean-content alternate (RSS/Atom/feed/markdown)plausibleNot checked — page did not render
- Serves markdown on Accept: text/markdownplausibleNot provided
- Interactive elements are semanticplausibleNot checked — page did not render
- Form fields have accessible namesplausibleNot checked — page did not render
- Inputs carry autocomplete hintsplausibleNot checked — page did not render
- WebMCP tools (modelContext API)emergingNot checked — page did not render
- AI retrieval/search fetchers allowed (robots.txt)provenno retrieval-fetcher blocks in robots.txt
- Sitemap (indexability)plausibleFound — www.crossmint.com/sitemap.xml
- schema.org JSON-LD in raw HTMLplausible1 valid JSON-LD block(s) in raw (pre-JS) HTML
- Content-Signal directives (robots.txt)emergingNot provided
- Web Bot Auth key directory (emerging)emergingNot provided
- Discovery Link headers on homepage (emerging)emergingNot provided
- Pricing visible without loginNot checked — homepage returned a challenge page
- robots.txt AI-crawler accessplausibleno AI-crawler blocks in robots.txt
Evidence & history
Last probed 2026-10-07 04:17 UTC. The raw JSON is the archival record.
| Date | Score | Badge | Rubric version |
|---|---|---|---|
| 2026-10-07 04:17 UTC | 76 | Moderate-Interrupt (current) | rubric v2026.4 |
| 2026-10-07 04:17 UTC | 76 | Moderate-Interrupt | rubric v2026.4 |
| 2026-09-07 01:51 UTC | 81 | Low-Interrupt | rubric v2026.4 |
| 2026-09-07 01:46 UTC | 81 | Low-Interrupt | rubric v2026.4 |
| 2026-08-09 23:47 UTC | 81 | Low-Interrupt | rubric v2026.4 |
| 2026-08-09 23:47 UTC | 81 | Low-Interrupt | rubric v2026.4 |
| 2026-08-09 17:13 UTC | 81 | Low-Interrupt | rubric v2026.4 |
| 2026-08-09 05:24 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 05:24 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 05:16 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 05:16 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 05:13 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 05:13 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 03:14 UTC | 88 | Low-Interrupt | rubric v2026.3 |
| 2026-08-09 01:47 UTC | 88 | Low-Interrupt | rubric v2026.2 |
| 2026-08-09 01:45 UTC | 88 | Low-Interrupt | rubric v2026.2 |
| 2026-07-10 07:16 UTC | 100 | Low-Interrupt | rubric v2026.1 |
Alternatives in Agent-Commerce Infrastructure
Other Agent-Commerce Infrastructure tools in the same mode (integrated), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.
- 95Overallx402 (Coinbase protocol)
x402.org · Agent-Commerce InfrastructureMR92 - 88OverallFewsats
fewsats.com · Agent-Commerce InfrastructureMR78 - 78triageOverallNekuda
nekuda.ai · Agent-Commerce InfrastructureMR74 - 75OverallChatGPT Instant Checkout / OpenAI ACP
openai.com · Agent-Commerce InfrastructureMR90 - 72Overallx402 Bazaar
coinbase.com · Agent-Commerce InfrastructureMR64