Glossier

glossier.com · E-commerce / D2C Retail modeTransactional

Last probed 2026-08-09 23:51 UTC · Provisional

GlossierD2C beauty brand, Shopify-powered, named ACP launch partner.

63 / 100triageInterrupt Score(range 3282 · 10 properties unassessed)How much automated use this service interrupts — the badge-driving metric. Unassessed properties are provisionally scored at 50%; evidence-graded successes at 25%.
Custody / RiskUnknown
ConfidenceProvisional

Verdict: An agent can discover, activate, and operate on its own. Manage isn't assessed yet.

  1. DiscoverEasy
  2. ActivateEasy
  3. OperateEasy
  4. ManageNot assessed

Checkout flow not yet probed (Tier 2). For a transactional listing the purchase path is where interrupts actually bite — this readout reflects only what passive and signup-level checks could observe, not a verified purchase.

Capability parity

Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage.

Discover

Can an agent find and read it, no account?

Easy
  • Be found by a retrieval agentEasy

    Retrieval access present.

    Evidence
    Path tried
    robots.txt / sitemap / discovery headers
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    retrieval_bot_access, sitemap_xml
  • Read what it does and how to use itEasy

    Machine-readable docs present.

    Evidence
    Path tried
    llms.txt / AGENTS.md / schema.org / docs
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    llms_txt, llms_full_txt, agents_md, markdown_content
  • Read pricing & limits without loginNot assessed

Activate

Can an agent sign up and walk away with the keys it needs?

Easy
  • Create an account self-serveEasy

    Signup inspected — no blocker found.

    Evidence
    Path tried
    signup flow
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
  • Obtain an API / MCP access credentialNot assessed
  • Obtain a management / admin keyNot assessed
  • Accept the terms without a bot-banEasy

    No bot-prohibition signal found.

    Evidence
    Path tried
    ToS / policy scan
    Where it stalled
    completed
    Evidence tier
    Tier 0 (passive scan)
    Verification
    Evidence-only — graded from passive signal, not live-verified.

Operate

Can an agent do the service's actual jobs — call, transact, pay?

Easy
  • Use the service's primary jobEasy

    Machine interface present — evidence-only, not live-verified.

    Evidence
    Path tried
    API / MCP / browser
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    webmcp
  • Complete a transaction / checkoutNot assessed

    Live checkout not yet attempted (Tier 2).

  • Pay via an agent rail (x402 / ACP / AP2)Easy

    Agent-payment metadata present.

    Evidence
    Path tried
    payment protocol / oauth metadata
    Where it stalled
    completed
    Evidence tier
    Tier 1 (unauth probe)
    Verification
    Evidence-only — graded from passive signal, not live-verified.
    Backing checks
    oauth_metadata, payment_protocol

Manage

Can an agent administer the account and provision resources?

Not assessed
  • Provision / scale / tear down a serviceNot assessed
  • Change account details / set budget / rotate keysNot assessed
  • View usage & billingNot assessed
  • Cancel / export / delete (offboard)Not assessed

Interrupt tier: Moderate-Interrupt — derived from 1 finding; interrupt score 63 / 100 — the badge-driving metric. (range 3282 · 10 unassessed)

Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.

Property coverage

A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.

PropertyStageStateEvidenceRequired
No Machine Interfaceoperate failedActive finding — itemized in the penalty matrix below. Tier 1 assesses this property.yes
SSO-only signup, no API-key issuanceactivate partialSome coverage exists, but the available evidence is incomplete. Tier 1 assesses this property.no
Email OTP verificationactivate unassessedTier 1 (unauth probe) ran but did not gather enough evidence to claim clean. Tier 1 assesses this property.no
SMS / phone OTP verificationactivate unassessedTier 1 (unauth probe) ran but did not gather enough evidence to claim clean. Tier 1 assesses this property.no
Mandatory phone verification callactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Mailed physical code (postal)activate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
“Contact sales” wall (no self-serve path)activate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Manual approval queueactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Rate-limit-triggered manual reviewmanage unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
One-time account / payment-method provisioningmanage unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Identity / KYC verificationactivate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
Crypto wallet / key-custody setupoperate unassessedNo probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property.no
CAPTCHA / bot-challengeactivate successNone found — checked at Tier 0 (passive scan) + Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property.no
ToS clause banning automated/bot accessdiscover successNone found — checked at Tier 0 (passive scan) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property.no
Mandatory redirect to vendor’s own siteoperate successNone found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property.no
Interrupt foundBase weight× Timing× Hardness× Evidence= Penalty
Starting score100
No Machine InterfaceoperateNeither an MCP server nor a usable API machine interface was found after Tier 0 and Tier 1 candidate checks.9×1one-time setup×2.5hard×0.8Tier 1 (unauth probe)−18
Total penalty18
Full unknown tax 118.2 — capped at 25 (point score uses 50% of the capped value)118.2
Evidence-graded tax (successes not live-verified by a Tier 2 probe) 120.2 — capped at 25 (point score uses 25% of the capped value)120.2
Raw score = 100 − 18 = 82
Point score = 82 − 50% × 25 − 25% × 25 = 63.3 → 63
63

How we scored this

Machine-readability checks 53 / 100

Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →

  • llms.txtemergingFound — www.glossier.com/llms.txt (4.2 KB, 5 links)
  • llms-full.txtemergingFound — www.glossier.com/llms-full.txt (4.2 KB, 5 links)
  • AGENTS.mdemergingFound — www.glossier.com/AGENTS.md
  • A2A agent cardemergingNot provided
  • MCP server (well-known or official registry)plausibleNot provided
  • OpenAPI/Swagger specplausibleNot provided
  • Rate-limit headersplausibleNot provided
  • Structured JSON error responsesplausibleNot provided
  • OAuth authorization-server metadata (RFC 8414)provenFound — www.glossier.com/.well-known/oauth-authorization-server
  • API catalog (RFC 9727) (emerging)emergingNot provided
  • Agent-payment discovery (x402 / UCP) (emerging)emergingUCP manifest: https://www.glossier.com/.well-known/ucp
  • Lean HTML transfer sizeplausible393 KB raw HTML (threshold 488 KB)
  • Manageable DOM sizeplausibleNot provided
  • High content-to-markup densityplausible2.9% text/HTML (11515 chars in 393 KB, threshold 2%)
  • Content readable without JS executionprovenraw HTML holds 471% of rendered text (11515 vs 2446 chars; threshold 40%)
  • Clean-content alternate (RSS/Atom/feed/markdown)plausibleNot provided
  • Serves markdown on Accept: text/markdownplausiblereturned text/markdown; charset=utf-8
  • Interactive elements are semanticplausibleNot provided
  • Form fields have accessible namesplausible27/29 named (93%)
  • Inputs carry autocomplete hintsplausibleNot provided
  • WebMCP tools (modelContext API)emerging10 tool(s) registered via the modelContext API during page load
  • AI retrieval/search fetchers allowed (robots.txt)provenno retrieval-fetcher blocks in robots.txt
  • Sitemap (indexability)plausibleFound — www.glossier.com/sitemap.xml
  • schema.org JSON-LD in raw HTMLplausibleNot provided
  • Content-Signal directives (robots.txt)emergingNot provided
  • Web Bot Auth key directory (emerging)emergingNot provided
  • Discovery Link headers on homepage (emerging)emergingNot provided
  • robots.txt AI-crawler accessplausibleno AI-crawler blocks in robots.txt
  • Unauthenticated API error is structured JSONplausibleNot provided
  • Unauthenticated API returns auth guidance (401/403 or documented)plausibleNot provided
  • API exposes rate-limit headersplausibleNot provided
  • API key obtainable without human interactionplausibleNot checked — no OpenAPI spec found; self-serve API-key path indeterminate from Tier 1

Evidence & history

Last probed 2026-08-09 23:51 UTC. The raw JSON is the archival record.

DateScoreBadgeRubric version
2026-08-09 23:51 UTC63Moderate-Interrupt (current)[email protected]
2026-08-09 23:51 UTC63Moderate-Interrupt[email protected]
2026-08-09 22:53 UTC63Moderate-Interrupt[email protected]
2026-08-09 17:13 UTC0Blocked[email protected]
2026-08-09 07:23 UTC0Blocked[email protected]
2026-08-09 05:33 UTC0Blocked[email protected]
2026-08-09 05:33 UTC0Blocked[email protected]
2026-08-09 03:14 UTC88Low-Interrupt[email protected]
2026-08-09 01:50 UTC88Low-Interrupt[email protected]
2026-08-09 01:45 UTC88Low-Interrupt[email protected]
2026-07-10 07:18 UTC100Low-Interrupt[email protected]

Alternatives in E-commerce / D2C Retail

Other E-commerce / D2C Retail tools in the same mode (transactional), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.

Embed this rating

Copy this snippet to display your Interrupt Index seal on your site — the seal image and link stay in sync with your latest probe automatically. Pick the variant that matches your site’s theme.

Light (default)

<a href="https://interruptindex.com/tools/glossier"><img src="https://interruptindex.com/badge/glossier.svg" alt="Glossier — Interrupt Index agent-readiness rating" height="64"></a>

Dark

<a href="https://interruptindex.com/tools/glossier"><img src="https://interruptindex.com/badge/glossier.svg?theme=dark" alt="Glossier — Interrupt Index agent-readiness rating" height="64"></a>