Hetzner
hetzner.com · Compute / VPS / Cloud Hosting modeIntegrated
Last probed 2026-09-08 04:41 UTC · Provisional
Hetzner — Self-serve budget VPS/dedicated servers (EU-based).
Verdict: Partially — an AI agent can use Hetzner, but activate is blocked — A CAPTCHA blocks automated signup.
- DiscoverNot yet probed
- ActivateBlocked
- OperateNot yet probedgated by Activate
- ManageNot yet probedgated by Activate
Capability parity
Each stage answers one question about what an agent can do unattended. Stages are ordered by the credential-gateway dependency: Activate issues the keys that unlock Operate and Manage. A row marked “Not yet probed” means no probe has tried that capability yet — a different ledger from the “unassessed” properties under Findings, where no probe tier capable of catching that interrupt has run.
Discover
Can an agent find and read it, no account?
No probe has attempted this stage yet: Be found by a retrieval agent; Read what it does and how to use it; Read pricing & limits without login.
- Be found by a retrieval agentNot yet probed
Retrieval access not confirmed - no robots/sitemap/discovery check passed.
- Read what it does and how to use itNot yet probed
No machine-readable docs found - llms.txt, AGENTS.md, and schema.org checks all failed or are absent.
- Read pricing & limits without loginNot yet probed
Public pricing was not confirmed - the page was absent, gated, or unreadable.
Activate
Can an agent sign up and walk away with the keys it needs?
Assessment incomplete - not yet probed: Obtain an API / MCP access credential; Obtain a management / admin key.
- Create an account self-serveBlocked
A CAPTCHA blocks automated signup.
CAPTCHA / bot-challenge blocks this.
Evidence
- Path tried
- signup flow
- Where it stalled
- verification step
- Evidence tier
- Tier 1 (unauth probe)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
- CAPTCHA / bot-challengeSignuphCaptcha widget detected on the account-signup form.
- Obtain an API / MCP access credentialNot yet probed
No self-serve credential signal detected - key issuance not yet probed.
- Obtain a management / admin keyNot yet probed
No scoped or administrative key path was confirmed after activation.
- Accept the terms without a bot-banEasy
No bot-prohibition signal found.
Evidence
- Path tried
- ToS / policy scan
- Where it stalled
- completed
- Evidence tier
- Tier 0 (passive scan)
- Verification
- Evidence-only — graded from passive signal, not live-verified.
Operate
Can an agent do the service's actual jobs — call, transact, pay?
No probe has attempted this stage yet: Call the primary service over MCP / API; Pay via an agent rail (x402 / ACP / AP2).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Call the primary service over MCP / APINot yet probed
No machine interface found by passive checks, and no live Tier-2 call attempted.
Gated by Activate — the credential this needs isn't issued unattended.
- Complete a transaction / checkoutNot applicable
Integrated tool — the API call is the transaction, no separate checkout.
Gated by Activate — the credential this needs isn't issued unattended.
- Pay via an agent rail (x402 / ACP / AP2)Not yet probed
No agent-payment metadata detected - payment rails not yet probed.
Gated by Activate — the credential this needs isn't issued unattended.
Manage
Can an agent administer the account and provision resources?
No probe has attempted this stage yet: Provision / scale / tear down a service; Change account details / set budget / rotate keys; View usage & billing; Cancel / export / delete (offboard).
Gated by Activate — the credential this stage needs isn't issued unattended, so these rows may be unreachable even where they read Easy.
- Provision / scale / tear down a serviceNot yet probed
Not probed - provisioning is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- Change account details / set budget / rotate keysNot yet probed
Not probed - account admin is not part of the probe suite yet.
Gated by Activate — the credential this needs isn't issued unattended.
- View usage & billingNot yet probed
Authenticated usage and billing access was not confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
- Cancel / export / delete (offboard)Not yet probed
No self-serve cancellation, export, or deletion path was confirmed.
Gated by Activate — the credential this needs isn't issued unattended.
Findings
How scoring works →Interrupt tier: High-Interrupt — derived from 3 findings; interrupt score 23 / 100 — the badge-driving metric. (range 0–42 · 7 unassessed)
Every tool starts at 100. Each interrupt found subtracts a penalty of base weight × timing × hardness × evidence — the multiplier values below come from the same rubric tables the score is computed with. New snapshots also provisionally subtract 50% of the full worst-case tax for each unassessed property and 25% for evidence-graded successes not live-verified by Tier 2.
Property coverage
A check only counts as clean when a probe tier capable of detecting that interrupt actually ran and found nothing. Not tested ≠ clean.
| Property | Stage | State | Evidence | Required |
|---|---|---|---|---|
| CAPTCHA / bot-challenge | activate | failed | Active finding — itemized in the penalty matrix below. Tier 0 assesses this property. | no |
| SMS / phone OTP verification | activate | failed | Active finding — itemized in the penalty matrix below. Tier 1 assesses this property. | no |
| Manual approval queue | activate | failed | Active finding — itemized in the penalty matrix below. Tier 2 assesses this property. | no |
| Mandatory phone verification call | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Mailed physical code (postal) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| “Contact sales” wall (no self-serve path) | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Rate-limit-triggered manual review | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| One-time account / payment-method provisioning | manage | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Identity / KYC verification | activate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Crypto wallet / key-custody setup | operate | unassessed | No probe tier that can detect this has run yet — unknown, not clean. Tier 2 assesses this property. | no |
| Email OTP verification | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| ToS clause banning automated/bot access | discover | success | None found — checked at Tier 0 (passive scan) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 0 assesses this property. | no |
| Mandatory redirect to vendor’s own site | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| SSO-only signup, no API-key issuance | activate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | no |
| No Machine Interface | operate | success | None found — checked at Tier 1 (unauth probe) (evidence-graded; not yet live-verified by a Tier 2 probe) Tier 1 assesses this property. | yes |
| Interrupt found | Base weight | × Timing | × Hardness | × Evidence | = Penalty |
|---|---|---|---|---|---|
| Starting score | 100 | ||||
| Manual approval queueRate-limit / manual review escalationFirst-time / low-history accounts are held in a manual fraud-review queue before larger instance types or additional servers can be provisioned. | 6 | ×3ongoing | ×2.5hard | ×0.8Tier 1 (unauth probe) | −36 |
| CAPTCHA / bot-challengeSignuphCaptcha widget detected on the account-signup form. | 6 | ×1one-time setup | ×2.5hard | ×0.8Tier 1 (unauth probe) | −12 |
| SMS / phone OTP verificationAccount verification (KYC / OTP)New account signup requires SMS/phone OTP verification before provisioning any server. | 5 | ×1one-time setup | ×2.5hard | ×0.8Tier 1 (unauth probe) | −10 |
| Total penalty | −58 | ||||
| Full unknown tax 89 — capped at 25 (point score uses 50% of the capped value) | −89 | ||||
| Evidence-graded tax (successes not live-verified by a Tier 2 probe) 142.4 — capped at 25 (point score uses 25% of the capped value) | −142.4 | ||||
| Raw score = 100 − 58 = 42 Point score = 42 − 50% × 25 − 25% × 25 = 23.3 → 23 | 23 | ||||
What would make this Easy
One concrete change per blocker found. These are the diffs between this listing's current parity and an unattended agent path.
- Activate — CAPTCHA / bot-challengeDrop the CAPTCHA, or gate it behind a documented bot-detection signal a well-behaved agent can pass.
- Activate — Manual approval queueOffer an instant self-serve tier, even a rate-limited one.
- Activate — SMS / phone OTP verificationAllow email-only verification, or offer SSO alongside an API-key path.
How we scored this
- Confidence: Provisional (0.55) — Based on Tier 0/1 evidence only (passive checks, no live transaction attempt) — treat the number as a triage signal, not a verified outcome.
- Machine-Readability sub-score: 65 / 100 (a separate integration-ease signal — it never enters the Interrupt Score or badge).
- Some capability stages are not yet probed — shown plainly in the spine above, never as a pass.
- Rubric, tiers, confidence model, and badge thresholds →
Machine-readability checks not yet recorded
Four check groups, equal weight: machine interfaces, browsing efficiency, element discoverability, and discovery/agent access. Each check carries an evidence grade (proven / plausible / emerging) — an honesty label that never weights the score. What these mean →
No per-check breakdown recorded for this listing.
Evidence & history
Last probed 2026-09-08 04:41 UTC. The raw JSON is the archival record.
This is the first assessment on record.
| Date | Score | Badge | Rubric version |
|---|---|---|---|
| 2026-09-08 04:41 UTC | 23 | High-Interrupt (current) | rubric v2026.4 |
Alternatives in Compute / VPS / Cloud Hosting
Other Compute / VPS / Cloud Hosting tools in the same mode (integrated), ranked by Overall LLM-Friendliness (the mean of Interrupt Score and Machine-Readability) — comparable to this listing because they share its usage mode.
- 84OverallFly.io
fly.io · Compute / VPS / Cloud HostingMR86 - 75OverallCoreWeave
coreweave.com · Compute / VPS / Cloud HostingMR69 - 73triageOverallvercel.com
vercel.com · Compute / VPS / Cloud HostingMR71 - 73OverallCloudflare
cloudflare.com · Compute / VPS / Cloud HostingMR66 - 64OverallRender
render.com · Compute / VPS / Cloud HostingMR63