An Agent Lands on Your Homepage — What Can It Actually Read? AgentBadge generated its entire machine-readable discovery surface from live code sources, publishing eleven manifests — including A2A agent-card.json, MCP server-card.json, llms.txt, and a did:web document — all served free and without authentication. The manifests are projections of the same runtime sources (OpenAPI spec, route config, blog data, SKU catalog) and are regenerated via `bun run gen:discovery`, with a `git diff --exit-code` check in CI that fails the build if any manifest drifts from code. The site also returns markdown via `Accept: text/markdown` and runs its own 142-rule readiness scanner against itself in CI, requiring a 100% pass. An AI agent evaluating a vendor does what a human does: it opens the site and looks for proof. The difference is speed and format — the agent gives you seconds, not minutes, and it wants JSON, not hero banners. Until recently, an agent landing on agentbadge.xyz found a page built for humans and nothing else — while our own readiness scanner was grading other sites on exactly the signals we lacked. The cobbler had no shoes. We fixed that: the entire discovery surface is now generated from live sources , served free with no auth, and verified by our own scanner in CI. Eleven machine-readable manifests, all 200 OK , all free, all generated — not hand-maintained: /.well-known/agent-card.json A2A v1.0 — who we are, skills /.well-known/api-catalog RFC 9727 linkset — every API entry /.well-known/erc8004-agent.json on-chain identity registration /.well-known/mcp/server-card.json MCP capabilities + tools surface /.well-known/agent-evaluation.json verification ladder claims→refs /.well-known/owner-questions.json "who runs this" for due-diligence /.well-known/did.json did:web:agentbadge.xyz document /.well-known/did-configuration.json signed domain linkage VC-JWT /.well-known/jwks.json real Ed25519 key, kid'd /.well-known/security.txt RFC 9116, Expires generated +1y /llms.txt agent-oriented sitemap The agent-card alone answers the A2A handshake: name, provider, supportedInterfaces , skills with tags and examples, and securitySchemes declaring x402 as the payment rail. One GET and a foreign agent knows our identity, capabilities, and how to pay. Not from a copywriter — from the code itself. A manifest registry collects the same live sources the runtime uses openapi.ts , route config, blog-data.ts , the SKU catalog , and every manifest is a projection of that truth: bun run gen:discovery writes snapshots under public/.well-known/ ; manual edits are banned. git diff --exit-code — if a manifest drifted from code, the build fails. Ours cannot go stale without the build telling us. llms.txt — the de-facto convention for telling an LLM "start here": H1 title, a blockquote describing the platform, sections of named links. Ours is generated with machine-readable entry points, quick start, free and paid endpoints — and the services section anchors into the same /api/v1/services catalog that powers the bazaar extension on every 402. Because the reader might not be a browser. Accept: text/markdown on any page returns the markdown representation — verified live: bash $ curl -sH "Accept: text/markdown" https://agentbadge.xyz/blog content-type: text/markdown; charset=utf-8 Blog articles carry .md mirrors too /blog/arc-c10-payer-binding.md → 200 text/markdown . HTML stays canonical;