Methodology

AI-native scoring

Every product in the catalog has a 0–100 AI-native score. The score is computed automatically from public catalog data using the weights and signals below. Disagree with a score? Open a submission to correct the underlying data.

Overview

The score is a weighted blend of four components. Each component scores a product on a small set of public signals, normalises by that component's maximum, and the weighted total is rounded to an integer from 0–100.

Component Weight Max raw points
Integration 35% 8
Trust 30% 6
Portability 20% 4
Security 15% 4

Tier bands

Tier Score
Tier S 90 +
Tier A 75 +
Tier B 55 +
Tier C 35 +
Tier D 0 – 34

Dimensions that don't apply

Some dimensions cannot apply to some products. A read-only data-retrieval API, for example, holds no user data, configuration, or artifact a customer would migrate on exit, so the Portability dimension has nothing to measure. Rather than score such a dimension zero — which would blur "cannot apply" with "applies but scores poorly" — a curator can mark a dimension not applicable for a product.

Three states stay distinct: Unknown (the dimension applies but hasn't been assessed — scored 0, still counted), None / low (the dimension applies and the product scores poorly — scored 0, still counted), and Not applicable (the dimension cannot apply — excluded entirely).

A not-applicable dimension is excluded from the denominator and its weight is redistributed proportionally across the remaining applicable dimensions, so the score stays on a 0–100 scale:

effective_weight(d) = nominal_weight(d) ÷ Σ nominal_weight over applicable dimensions

With no not-applicable dimensions this is identical to the standard math. A product must keep at least 2 applicable dimensions and applicable dimensions worth at least 50% of the nominal weight; a declaration that would drop below either bound is rejected. Every not-applicable declaration requires a written justification and is approved by a curator through the submission workflow — there is no self-approval path.

Integration — 35%, max 8 raw points

How easy it is for an agent to drive the product end-to-end without a human keyboard in the loop.

Signal Points Detail
MCP server +2 First-class Model Context Protocol surface.
A2A server +1 Agent-to-agent protocol surface.
API spec +1 Machine-readable OpenAPI, gRPC, or GraphQL contract.
Web-MCP +1 MCP capability exposed in the web app itself.
Agent skill +1 Published Claude Code / agent skill.
Headless signup +1 An agent can create an account without a CAPTCHA / human step.
Native connector +1 Listed as a first-class connector in any host LLM platform's directory (e.g. Claude, ChatGPT, Gemini, Cursor).

Trust — 30%, max 6 raw points

Whether the vendor's data handling makes it safe for an agent to send real data through the product.

Signal Points Detail
Zero data retention 0 / +1 / +2 Vendor does not retain request data; "available" earns +1, "yes" earns +2.
No training on user data 0 / +1 / +2 Vendor does not train on customer data; "available" earns +1, "yes" earns +2.
Sandbox environment 0 / +1 / +2 Dedicated test / sandbox account with no real-world side effects.

Portability — 20%, max 4 raw points

How cheap it is to leave — measured across both data portability (getting a data corpus in and back out) and integration / switching portability (open formats, standard protocols, no proprietary-SDK lock-in, self-hostability, open-source availability). The total is capped at the dimension max, so a product strong in any family reaches full marks; no delivery model is penalized for lacking another family's affordances.

Signal Points Detail
Data export 0 / +1 / +2 Export of customer data; "partial" earns +1, "full" earns +2.
Data import 0 / +1 / +2 Import of customer data; "partial" earns +1, "full" earns +2.
Open standards +1 Interoperates with open standards rather than proprietary formats.
Standard protocol access +1 Accessible over a standard protocol (HTTP/OpenAPI, gRPC, GraphQL) rather than a proprietary-only client.
No proprietary-SDK lock-in +1 Usable without a single-vendor SDK.
Documented provider swap +1 Documents a provider-swap path or adheres to a portable interface standard.
Self-hostable +1 Can run on user-controlled infrastructure rather than only as a hosted service.
Open source +1 Core is distributed under an open-source license.

Security — 15%, max 4 raw points

Whether enterprise-grade access controls and audited compliance claims are in place.

Signal Points Detail
Multi-factor authentication +1 / +2 MFA available earns +1; MFA enforced earns +2.
Compliance certifications +1 At least one named compliance certification (SOC 2, HIPAA, etc.).
Access controls +1 RBAC, ABAC, or similar tagged access-control system.