Agent Experience (AX) Tier List

By 2027, AI agents will be the primary power users of the web.

This list asks one question: can an AI agent start using a service without a human in the loop?

Want to improve your AX? Get a detailed report with your insights.

Get report

35 of 35 providers

DetailsProviderTierDiscoveryLogin flowBot protectionPaywallSign-up
SHands-off
No credential needed, nothing to findLibrary, no accountNoneFreemium, no cardNot needed
SHands-off
FoundClaim CLI, no accountNoneFreemium, no cardNot needed
SHands-off
Foundauth.md provision + claimNoneFreemium, no cardNot needed
SHands-off
FoundGlobal npm CLI, no accountNoneFreemium, no cardNot needed
SHands-off
Only when pointedAnonymous deployNoneFreemium, no cardNot needed
SHands-off
Only when pointedPuzzle keyNoneFreemium, no cardNot needed
SHands-off
Only when pointedPre-provisioned scaffold + claimNoneFreemium, no cardNot needed
SHands-off
Never foundx402 gateway, no accountNonePay-per-call, no cardNot needed
SHands-off
Never foundx402 gateway, no accountNonePay-per-call, no cardNot needed
SHands-off
Never foundUnauthenticated project + claimNoneFreemium, no cardNot needed
SHands-off
Never foundClaim, no accountNoneFreemium, no cardNot needed
SHands-off
Never foundClaim CLI, no accountNoneFreemium, no cardNot needed
SHands-off
Never foundAnonymous provision + claimNoneFreemium, no cardNot needed
AJust confirm
FoundHeadless CLI signupNoneFreemium, no cardEmail + password, headless
AJust confirm
Never foundCLI loginNoneFreemium, no cardOne click
BCopy a key
No better path for an agent to findOne keyNoneCard on fileOne click
BCopy a key
FoundOne keyNoneFreemium, no cardOne click
BCopy a key
FoundOne keyNoneFreemium, no cardOne click
BCopy a key
FoundOne keyNoneFreemium, no cardOne click
BCopy a key
FoundOne keyreCAPTCHACard on fileOne click
BCopy a key
FoundOne keyNoneFreemium, no cardOne click
BCopy a key
Found, didn't workOne keyVercel Security CheckpointFreemium, no cardOne click
BCopy a key
Found, didn't workOne keyLogin blocked by CloudflareFreemium, no cardOne click
BCopy a key
Never foundauth.md device code grantNoneCard on fileDashboard signup, 404 from docs
BCopy a key
Never foundOne keyNoneFreemium, no cardEmail + OTP
CFigure it out
FoundID + secretNoneFreemium, no cardOne click
CFigure it out
FoundSelf signup blocked, needs human OTPConsole captcha + domain blocklistFreemium, no cardEmail + OTP
CFigure it out
Found4 valuesreCAPTCHAFreemium, no cardEmail
CFigure it out
FoundOne keyCaptchaFreemium, no cardApproval
CFigure it out
Found, didn't workOne key, dashboard blockedVercel Security CheckpointFreemium, no cardOne click
CFigure it out
Found, didn't workDevice code, expires 5minNoneFreemium, no cardOne click
DBlocked
No better path for an agent to findCLI sign-upSignup captchaEnterprise-only API keysEmail + OTP
DBlocked
FoundConnection stringNoneCard requiredOne click
DBlocked
Found, didn't workBrowser OAuth, token invalidNoneCard on fileNo self-serve
DBlocked
Found, didn't workPK + SK + hostOAuth redirect loop after 2FAFreemium, no cardOne click fails
Methodology
  • A single blocking step is enough to stop agentic user activation, so a provider's tier is set by its weakest criterion.
  • The Tier column shows the best path a provider offers; the Discovery column says whether the agents in our runs actually found it.
  • When a provider offers more than one way in, we grade the easiest one that works for an agent. A captcha or a login wall on a route the agent never has to take does not count against it.
  • Runs come from our eval program between June and September 2026, which spans Claude Opus, Sonnet and Haiku, plus GPT-5.6 and Grok harnesses.
  • Login flow and paywall are mostly verified from our own runs, while bot protection and sign-up are mostly read from provider documentation.
  • Every piece of evidence in a provider's detail row names its source: a 2027.dev eval run, the provider docs, or our own check.
  • A run only overrides documentation where the agent actually attempted that path.

What tiers mean

TierWhat it costs youLogin flowBot protectionPaywallSign-up
SHands-off
User does nothing. Agent starts using the service autonomouslyAnonymous or claimable resource, agent-auth (auth.md, x402)NoneFreemium, no cardNot needed
AJust confirm
User only confirms actions. Straightforward flowCLI login (device code, OAuth confirm)None, or agent-solvableFreemium, no cardGoogle or GitHub, one click
BCopy a key
User, or their browser agent, does a simple action on the websiteOne key, copied from a dashboardSign up only, one captchaFreemium, card on fileEmail + OTP
CFigure it out
User, or their browser agent, has to think, read, understand how the integration works, or take multiple complicated actions2+ keys, multi-step, keys hard to findSign in + sign upFree trial, card requiredEmail + verify domain or approval
DBlocked
User can't startNo self-serve pathBlocks everythingPaid only, sales callInvite, waitlist, KYC

What the criteria mean

  • Login flow: Can the agent get a working credential itself, or must a human paste in a key?
  • Bot protection: Does a captcha or similar challenge stop it?
  • Paywall: Can it start for free, or does it need a card or a sales call?
  • Sign-up: Can an account be created without a human?
Don't see your tool?Request an evaluation