UCP Checker
Back to status
hawkshift.com icon
UCP Score

UCP Score for hawkshift.com

UCP conformance score, top priorities, impact & effort matrix, and copy-paste fixes for every issue.

✓Verified
B78/100
Analyzed Oct 8, 2026 · 2 recommendations ·Custom · v2026-08-25 latest
78
/ 100
UCP Conformance Score
B

Solid UCP setup on hawkshift.com with a few gaps left to close.

Agent Discovery95
UCP Conformance88
Capability Coverage48
Working

Agent Discovery is solid (95/100).

Start Here

Publish the public keys agents use to check your messages → Publish a /llms.txt brand brief

Verified

hawkshift.com publishes a valid UCP profile, with minor schema warnings.

Latency
139ms
Version
2026-08-25
Robots.txt
Allowed ✅

Top Priorities

1
Publish the public keys agents use to check your messages

Your UCP profile lists no public keys, so an agent cannot confirm that a message really came from your store.

Medium impact Medium effort
2
Publish a /llms.txt brand brief

No /llms.txt file detected at the root of your domain.

Low impact Low effort Emerging

Impact & Effort Matrix

Prioritised recommendations by expected impact and implementation effort

Quick Wins(0)

High impact, low effort

  • No items
Strategic Investments(0)

High impact, high effort

  • No items
Incremental Gains(1)

Medium impact & effort

  • Publish the public keys agents use to check your messages
Consider Later(1)

Lower priority

  • Publish a /llms.txt brand brief

How you compare on Custom

Response time benchmarked against 124 Customs we monitor.

fastCustom median 359msslow
Your store
139ms
Custom percentile
Top quartile
Faster than 85% of Custom stores
Cohort range
165–645ms
p25 to p75 (middle half)
Headless / custom stackCustom-built storefronts have the most flexibility but also the most surface area for inconsistency between environments. Run the score in staging before each deploy that touches profile, schemas, or transports.

Recommendations

All improvements ranked by priority, with evidence and actionable fixes.

1

Publish the public keys agents use to check your messages

Medium impact Medium effort

Your UCP profile lists no public keys, so an agent cannot confirm that a message really came from your store.

Why it matters

Agents use these keys to check that checkout messages really came from you. A store that takes payment through the agent needs them. A store that sends the buyer to its own checkout page can manage without them for now.

Show fix

Create an Ed25519 key pair. Add the public key to a "keys" list at the top level of your UCP profile, as in the example, and keep the private key on your server. Replace the key once a year, giving each new key its own "kid".

{
  "keys": [
    {
      "kty": "OKP",
      "crv": "Ed25519",
      "x": "<base64url-encoded-public-key>",
      "kid": "key-2026-04",
      "alg": "EdDSA"
    }
  ],
  "ucp": { ... }
}
UCP_MISSING_SIGNING_KEYS
2

Publish a /llms.txt brand brief

Low impact Low effort Emerging

No /llms.txt file detected at the root of your domain.

Why it matters

llms.txt is an emerging convention (analogous to robots.txt) that lets you give AI agents a hand-written brief about your brand, product categories, return policy, and crawl preferences. Strict UCP agents do not require it, but recommendation/discovery agents increasingly read it for context.

Show fix

Save as /llms.txt at your site root. Plain text, written for an LLM audience. The format is informal: these section headings are a working convention, not a spec. Replace the placeholders with your own brand details and update when policies or product lines change.

# llms.txt
# Public brief for AI agents about Yourstore

# About
One or two sentences on what you sell, who you sell to, and any defining context (founded, mission, sustainability stance, etc.).

# Product Categories
- Category one
- Category two
- Category three

# Policies
- Returns: e.g. 30 days, full refund
- Shipping: e.g. Free over $30, 3-5 business days
- Any other policy worth surfacing (cruelty-free, vegan, made-to-order, etc.)

# Agent Capabilities
- UCP manifest: /.well-known/ucp
- Supported flows: cart, checkout, tokenized payment, etc.
- Anything explicitly NOT supported (e.g. "no subscription products via agent")

# Contact
[email protected]
UCP_MISSING_LLMS_TXT

Full Check Breakdown

Every signal we evaluate, grouped by category.

Agent Discovery7/8 passed

Can AI agents find your store and its UCP profile?

  • HTTPSCore

    Profile served over a secure connection.

    Profile URL uses https://

    Why it matters

    Agents reject non-HTTPS endpoints outright. Signed payloads over HTTP are meaningless because the channel itself is tamperable.

  • UCP profile reachableCore

    Profile fetched OK from /.well-known/ucp.

    HTTP 200

    Why it matters

    Agents start every session by fetching this URL. If it 404s or times out, the store is invisible to agent commerce.

  • AI bot accessCore

    robots.txt allows agent crawlers to fetch the profile.

    robots.txt allows /.well-known/ucp

    Why it matters

    Agents respect robots.txt. Even a published profile gets ignored if the file is disallowed for known agent user-agents.

  • llms.txtExperimental

    Hand-written brief at /llms.txt for AI agents.

    HTTP 404 at /llms.txt

    Why it matters

    Emerging convention (analogous to robots.txt). Recommendation/discovery agents read it for brand context, return policy, and crawl preferences.

  • sitemap.xmlCore

    XML sitemap published at /sitemap.xml.

    Found at /sitemap.xml

    Why it matters

    Tells agents which pages are canonical and how often they change. Without it, agents fall back to following internal links.

  • Open Graph tagsCore

    OG meta tags on the homepage.

    og:title and og:type/url present

    Why it matters

    OG tags drive how your store unfurls in agent surfaces, Slack, iMessage, and ChatGPT shares.

  • Organization schema (JSON-LD)Core

    Schema.org Organization (or OnlineStore) JSON-LD on homepage.

    Organization-typed JSON-LD detected

    Why it matters

    Gives agents a structured representation of your brand identity — used to verify you are who your profile claims you are.

  • Mobile viewport metaCore

    Viewport meta tag for mobile rendering.

    <meta name="viewport"> present

    Why it matters

    Mobile agent sessions render in browser sandboxes that respect this. Without it, screenshots taken by agents are unreadable.

UCP Conformance2/4 passed

Does your profile meet the published spec?

  • Profile passes schema validationCore

    Profile structure conforms to the published UCP spec.

    No structural errors

    Why it matters

    Strict UCP agents reject profiles with structural errors. The error code in the diagnostic shows which field failed.

  • Protocol version present and well-formedCore

    ucp.version follows YYYY-MM-DD format.

    Version: 2026-08-25

    Why it matters

    UCP versions are dates, not semver. Agents pick the closest matching schema based on this string.

  • Signing keys publishedCore

    Root-level keys array (canonical since 2026-07-12; legacy signing_keys also accepted) for response verification.

    No signing_keys at root (common for managed/redirect-checkout stores)

    Why it matters

    Required for tokenized payment flows in v2026-04-08+. Stores using checkout-link redirects (e.g. WooCommerce native) often skip this safely.

  • No validation warningsCore

    Profile passes structural and field-level rules.

    1 warning

    Why it matters

    Each warning is a strict-spec deviation — the recommendations section above lists them with copy-code fixes.

Capability Coverage1/4 passed

What operations can agents actually perform?

  • Capabilities declaredCore

    Number of agent-readable capabilities under ucp.capabilities.

    1 capability detected

    Why it matters

    Capabilities tell agents what operations to attempt. More coverage = more sessions complete end-to-end without falling back to scraping.

  • Checkout capabilityCore

    Store declares a checkout-namespaced capability.

    No checkout capability

    Why it matters

    Without a checkout capability, agents can browse but can't complete a purchase end-to-end.

  • Transports declaredInterop

    Service transports (REST/MCP/A2A/Embedded) declared on services.

    REST, MCP

    Why it matters

    Transports tell agents how to actually call your endpoints. MCP and REST are the most widely supported today.

  • Payment handlersCore

    Tokenized payment handlers registered for in-conversation checkout.

    Empty array: checkout-link redirect strategy

    Why it matters

    Tokenized payment lets agents complete purchases without redirecting the buyer to a hosted checkout. Empty by design is valid for WooCommerce-style native checkouts.

Capabilities Detected

UCP capabilities supported by this endpoint
Com Hawkshift Ask ✓ Bound 2026-10-08
Catalog Lookup ⚠ Off-authority 2026-08-25
Catalog Search ⚠ Off-authority 2026-08-25

Technical Vitals

Technical details for this UCP endpoint
UCP Status Verified
Endpoint https://hawkshift.com/.well-known/ucp
HTTP Status 200
UCP Version 2026-08-25
Transports REST, MCP
Last Observed
Last Full Index

Embed your UCP Score

Drop the live grade into your README, status page, or marketing site. The badge auto-updates as your score changes.

UCP Score for hawkshift.com badge for https://ucpchecker.com/score/hawkshift.comLive preview
Markdown
[![UCP Score for hawkshift.com](https://ucpchecker.com/score/hawkshift.com/badge.svg)](https://ucpchecker.com/score/hawkshift.com)
HTML
<a href="https://ucpchecker.com/score/hawkshift.com"><img src="https://ucpchecker.com/score/hawkshift.com/badge.svg" alt="UCP Score for hawkshift.com"></a>
New · Early access open
Is hawkshift.com yours? Claim it & monitor it daily

Prove ownership with one DNS record and the new monitoring dashboard watches it every day — score trends, break alerts, staging drift and a watchlist that benchmarks you against the field. Free while in beta.

Start monitoring →

This score reflects data from the most recent crawl. Run a fresh check to update, or read the methodology to see how each signal is scored.

Save this report

Track hawkshift.com's UCP score over time. We'll re-run the full check weekly and email you if the score drops, a capability regresses, or status flips.

Free. One email when something changes — no marketing. Privacy.