Crossmint
crossmint.com · Agent-Commerce Infrastructure modeIntegrated
Last probed 2026-08-09 23:47 UTC · Provisional
Crossmint — Agent payments/wallets/checkout API spanning cards + stablecoins across 1B+ SKUs.
Verdict: An agent can discover, activate, and operate on its own. Manage isn't assessed yet.
- DiscoverEasy
- ActivateEasy
- OperateEasy
- ManageNot assessed
Capability parity
Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage.
Discover
Can an agent find and read it, no account?
- Be found by a retrieval agentEasy
Retrieval access present.
Evidence
- Path tried
- robots.txt / sitemap / discovery headers
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
retrieval_bot_access, sitemap_xml
- Read what it does and how to use itEasy
Machine-readable docs present.
Evidence
- Path tried
- llms.txt / AGENTS.md / schema.org / docs
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
llms_txt, llms_full_txt, agent_card, schema_org_jsonld
- Read pricing & limits without loginNot assessed
Activate
Can an agent sign up and walk away with the keys it needs?
- Create an account self-serveEasy
Signup inspected — no blocker found.
Evidence
- Path tried
- signup flow
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Obtain an API / MCP access credentialEasy
Self-serve credential path detected.
Evidence
- Path tried
- docs → key issuance
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
api_key_self_serve
- Obtain a management / admin keyNot assessed
- Accept the terms without a bot-banEasy
No bot-prohibition signal found.
Evidence
- Path tried
- ToS / policy scan
- Where it stalled
- completed
- Evidence tier
- Tier 0 (passive scan)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
Operate
Can an agent do the service's actual jobs — call, transact, pay?
- Call the primary service over MCP / APIEasy
Machine interface present — evidence-only, not live-verified.
Evidence
- Path tried
- API / MCP / browser
- Where it stalled
- completed
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- Backing checks
openapi_spec
- Complete a transaction / checkoutNot applicable
Integrated tool — the API call is the transaction, no separate checkout.
- Pay via an agent rail (x402 / ACP / AP2)Not assessed
Manage
Can an agent administer the account and provision resources?
- Provision / scale / tear down a serviceNot assessed
- Change account details / set budget / rotate keysNot assessed
- View usage & billingNot assessed
- Cancel / export / delete (offboard)Not assessed
Findings
How scoring works →Interrupt tier: Low-Interrupt — no interrupts found; interrupt score 81 / 100 — the badge-driving metric. (range 50–100 · 8 unassessed)
Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.
Property coverage
A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.
| Property | Stage | State | Evidence | Required |
|---|---|---|---|---|
| Mandatory phone verification call | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Mailed physical code (postal) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| “Contact sales” wall (no self-serve path) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Manual approval queue | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Rate-limit-triggered manual review | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| One-time account / payment-method provisioning | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Identity / KYC verification | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Crypto wallet / key-custody setup | operate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| CAPTCHA / bot-challenge | activate | success | None found — checked at Tier 0 (passive scan) + Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Email OTP verification | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| SMS / phone OTP verification | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| ToS clause banning automated/bot access | discover | success | None found — checked at Tier 0 (passive scan) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Mandatory redirect to vendor’s own site | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| SSO-only signup, no API-key issuance | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| No Machine Interface | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | yes |
No interrupts found — no evidence penalties. Unassessed properties still contribute a provisional tax.
How we scored this
- Confidence: Provisional (0.55) — Based on Tier 0/1 evidence only (passive checks, no live transaction attempt) — treat the number as a triage signal, not a verified outcome.
- Machine-Readability sub-score: 62 / 100 (a separate integration-ease signal — it never enters the Interrupt Score or badge).
- Some capability stages are not yet assessed — shown plainly in the spine above, never as a pass.
- Rubric, tiers, confidence model, and badge thresholds →
Machine-readability checks 62 / 100
Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →
- llms.txtemergingFound — docs.crossmint.com/llms.txt (64.8 KB, 439 links)
- llms-full.txtemergingFound — docs.crossmint.com/llms-full.txt (1024.0 KB, 611 links)
- AGENTS.mdemergingNot provided
- A2A agent cardemergingFound — docs.crossmint.com/.well-known/agent-card.json
- MCP server (well-known or official registry)plausibleNot provided
- OpenAPI/Swagger specplausibleFound — www.crossmint.com/openapi.yaml
- Rate-limit headersplausibleNot provided
- Structured JSON error responsesplausibleNot provided
- OAuth authorization-server metadata (RFC 8414)provenNot provided
- API catalog (RFC 9727) (emerging)emergingNot provided
- Agent-payment discovery (x402 / UCP) (emerging)emergingNot provided
- Lean HTML transfer sizeplausible126 KB raw HTML (threshold 488 KB)
- Manageable DOM sizeplausibleNot checked — page did not render
- High content-to-markup densityplausible6.5% text/HTML (8403 chars in 126 KB, threshold 2%)
- Content readable without JS executionprovenNot checked — raw and/or rendered text unavailable
- Clean-content alternate (RSS/Atom/feed/markdown)plausibleNot checked — page did not render
- Serves markdown on Accept: text/markdownplausibleNot provided
- Interactive elements are semanticplausibleNot checked — page did not render
- Form fields have accessible namesplausibleNot checked — page did not render
- Inputs carry autocomplete hintsplausibleNot checked — page did not render
- WebMCP tools (modelContext API)emergingNot checked — page did not render
- AI retrieval/search fetchers allowed (robots.txt)provenno retrieval-fetcher blocks in robots.txt
- Sitemap (indexability)plausibleFound — www.crossmint.com/sitemap.xml
- schema.org JSON-LD in raw HTMLplausible1 valid JSON-LD block(s) in raw (pre-JS) HTML
- Content-Signal directives (robots.txt)emergingNot provided
- Web Bot Auth key directory (emerging)emergingNot provided
- Discovery Link headers on homepage (emerging)emergingNot provided
- robots.txt AI-crawler accessplausibleno AI-crawler blocks in robots.txt
- Unauthenticated API error is structured JSONplausibleFound — api.crossmint.com/ (HTTP 421)
- Unauthenticated API returns auth guidance (401/403 or documented)plausibleNot provided
- API exposes rate-limit headersplausibleNot provided
- API key obtainable without human interactionplausibleOpenAPI spec published and signup is not SSO-only
Evidence & history
Last probed 2026-08-09 23:47 UTC. The raw JSON is the archival record.
| Date | Score | Badge | Rubric version |
|---|---|---|---|
| 2026-08-09 23:47 UTC | 81 | Low-Interrupt (current) | [email protected] |
| 2026-08-09 23:47 UTC | 81 | Low-Interrupt | [email protected] |
| 2026-08-09 17:13 UTC | 81 | Low-Interrupt | [email protected] |
| 2026-08-09 05:24 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 05:24 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 05:16 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 05:16 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 05:13 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 05:13 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 03:14 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 01:47 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-08-09 01:45 UTC | 88 | Low-Interrupt | [email protected] |
| 2026-07-10 07:16 UTC | 100 | Low-Interrupt | [email protected] |
Alternatives in Agent-Commerce Infrastructure
Other Agent-Commerce Infrastructure tools in the same mode (integrated), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.
- 89Overallx402 (Coinbase protocol)
x402.org · Agent-Commerce InfrastructureMR92 - 88OverallFewsats
fewsats.com · Agent-Commerce InfrastructureMR78 - 79OverallNekuda
nekuda.ai · Agent-Commerce InfrastructureMR77 - 75OverallChatGPT Instant Checkout / OpenAI ACP
openai.com · Agent-Commerce InfrastructureMR90 - 72Overallx402 Bazaar
coinbase.com · Agent-Commerce InfrastructureMR64