Heimdall Agent readiness survey · Radar top-1M

How it works

Heimdall downloads the Cloudflare Radar top-1M domain list — an unordered bucket of the million most-queried domains through 1.1.1.1. The list contains apex domains only (e.g. shopify.com, not mcp.shopify.com).

Each domain is checked two ways in parallel. First, @cloudflare/agent-readiness-scanner (internal Cloudflare package) probes the apex domain for MCP server card (/.well-known/mcp.json), A2A agent card (/.well-known/agent.json), agent skills, OAuth protected resource, API catalog, robots.txt, sitemap, and markdown negotiation — scoring 0–5. Second, a direct /mcp transport probe checks four URL variants per domain: domain/mcp, www.domain/mcp, mcp.domain, and mcp.domain/mcp. Auth is only flagged when there is a concrete signal — a WWW-Authenticate header, Cloudflare Access headers, or a redirect to a login/OAuth URL. A bare 403 with no auth headers is treated as not found.

Signal detection across scanned domains

Domains with MCP server card