Agent report card
Can an agent use GitHub REST API through Repository operations?
Grade B: Only part of the applicable terms is machine-readable.
GitHub / active
Five-stage assessment
Where agent autonomy holds and where it breaks
First break: Evaluate
Evaluate
LimitedOnly part of the applicable terms is machine-readable.
An ARD declaration has not been established.
An agent can discover the product and funnel from the tested public entrypoints.
Eligibility can be decided from explicit public criteria.
Pricing or the absence of a charge is explicit and machine-readable.
Evidence and actions
ARD declaration unknown
missing: unknownAn ARD declaration has not been established.
Decidable eligibility
supported: freshEligibility can be decided from explicit public criteria.
Eligibility criteria for GitHub services are explicitly detailed in the terms of service, including account requirements, age limits, and trade control restrictions.
Machine discovery
supported: freshAn agent can discover the product and funnel from the tested public entrypoints.
GitHub REST API documentation explicitly details the product and repository operation endpoints, enabling full machine discovery.
Readable pricing
supported: freshPricing or the absence of a charge is explicit and machine-readable.
Pricing information is explicitly detailed across public plan tiers including free options for public and private repositories.
Structured terms limited
supported: freshOnly part of the applicable terms is machine-readable.
Terms of Service are provided as structured HTML documentation on public web pages rather than a machine-readable schema endpoint.
What would improve this stage
- Publish complete applicable terms in a stable machine-readable document.
Sign up
LimitedOnly part of the signup flow is machine-operable.
Whether CAPTCHA blocks signup has not been established.
A stable signup entrypoint is available.
The tested signup path does not require phone or SMS verification.
A scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
Evidence and actions
CAPTCHA-free signup unknown
supported: freshWhether CAPTCHA blocks signup has not been established.
Documentation alone cannot establish the absence or presence of a CAPTCHA during the sign-up process.
Machine-operable signup limited
supported: freshOnly part of the signup flow is machine-operable.
The sign-up flow includes documented web steps and email verification prompts, requiring human intervention rather than a fully machine-operable automated API endpoint.
Phone-free signup
supported: freshThe tested signup path does not require phone or SMS verification.
The documented signup steps require an email address and email verification, but do not require phone or SMS verification.
Stable signup entrypoint
supported: freshA stable signup entrypoint is available.
A stable public signup entrypoint is available at https://github.com/signup.
Supported identity flow
supported: freshA scoped, revocable machine identity flow is documented, including explicit human authorization boundaries.
GitHub REST API documents scoped, revocable machine authentication methods including fine-grained personal access tokens and GitHub Apps with explicit authorization boundaries.
What would improve this stage
- Expose labelled, deterministic controls and documented validation without requiring hidden human interaction.
Pay
ReadyThe required price or no-charge status is explicit before commitment.
Machine-operable checkout has not been established.
A supported payment rail has not been established.
The tested funnel can complete without sales intervention.
Evidence and actions
Explicit price
supported: freshThe required price or no-charge status is explicit before commitment.
GitHub explicitly lists pricing details on its pricing page, including $0 USD per month for the Free plan, $4 USD per user/month for the Team plan, and $21 USD per user/month for Enterprise.
Machine-operable checkout unknown
supported: freshMachine-operable checkout has not been established.
Retained evidence describes the signup documentation and general account creation steps, but does not provide headless operational observations to verify machine-operable checkout controls.
Sales-free purchase
supported: freshThe tested funnel can complete without sales intervention.
Users can sign up for a GitHub personal account directly online via the sign-up page or social logins without requiring sales intervention.
Supported payment rail unknown
supported: freshA supported payment rail has not been established.
Retained headless evidence from the account documentation does not establish or demonstrate supported payment rails during the signup flow.
Provision
ReadySuccessful onboarding automatically activates usable access.
A bounded provisioning delay has not been established.
Usable credentials or delegated access are delivered through a documented flow.
Provisioning exposes machine-readable progress, terminal states, and reconciliation.
Evidence and actions
Automatic activation
supported: freshSuccessful onboarding automatically activates usable access.
Organization repositories are automatically created and activated upon calling the POST /orgs/{org}/repos REST API endpoint.
Bounded provisioning delay unknown
supported: freshA bounded provisioning delay has not been established.
The retained documentation does not specify a documented time bound or completion guarantee for repository creation.
Credential delivery
supported: freshUsable credentials or delegated access are delivered through a documented flow.
GitHub REST API documents standard credential delivery mechanisms including personal access tokens, GitHub App access tokens, and workflow GITHUB_TOKENs.
Machine-readable provisioning status
supported: freshProvisioning exposes machine-readable progress, terminal states, and reconciliation.
Repository creation responds synchronously with a full JSON representation of the created repository object, including machine-readable status fields.
Operate
ReadyA documented API or tool interface is available for operation.
An agent protocol interface has not been established.
Authentication is documented and usable within an agent authorization boundary.
Limits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Credential rotation, revocation, retry, and recovery paths are documented within delegated authority.
Evidence and actions
Agent protocol interface unknown
missing: unknownAn agent protocol interface has not been established.
API or tool access
supported: freshA documented API or tool interface is available for operation.
GitHub REST API documentation provides documented API endpoints and interfaces for repository operations.
Delegated recovery
supported: freshCredential rotation, revocation, retry, and recovery paths are documented within delegated authority.
Troubleshooting documentation provides credential revocation guidelines, retry waiting periods using headers, and failure recovery steps.
Documented limits and errors
supported: freshLimits, structured errors, retry behavior, and idempotency semantics are documented where applicable.
Repository operations endpoints document rate limits, structured HTTP error status codes, and request parameter validation rules.
Usable authentication
supported: freshAuthentication is documented and usable within an agent authorization boundary.
REST API documentation establishes usable token-based authentication via personal access tokens, GitHub Apps, and GITHUB_TOKEN Bearer headers.
What works
- Pay: The required price or no-charge status is explicit before commitment.
- Provision: Successful onboarding automatically activates usable access.
- Operate: A documented API or tool interface is available for operation.
What blocks agents
- Evaluate: Only part of the applicable terms is machine-readable.
- Sign up: Only part of the signup flow is machine-operable.
Improve the report
Correct it, rerun it, or improve the funnel
Every request carries the exact profile revision, projection, declaration, and Catalog release.
Method, policy, and immutable identifiers
Complete, fresh evidence for the core service lifecycle first applies hard stage severity, then grades the share of applicable evidenced signals that are constrained. Optional blocker probes affect the grade when established and remain visible as unknown when public evidence cannot establish them.
Any incomplete, contradictory, unsupported, or non-fresh required evidence produces an unrated profile. A failed Evaluate, Sign up, or Pay stage derives D; a failed Provision or Operate stage derives F; otherwise constrained-signal ratio derives A+ through C.
- Profile ID
- arp_01kzf0m4x9v5n7pd3j2gc8q1fk
- Revision
- sha256:ff20bd0db7f9047c42b074b682e802c235f4fb273f1394dddd60191e6f5d2e8f
- Projection
- sha256:30794560ae2486f217717f025c549a7c0d570ab1248a116a15ccdde4acf0ab3f
- Policy
- service-lifecycle-2026-08-08-calibrated: sha256:334e56852b5c38e178fcea839cfba680fb82dd96693842d933776baed21d63df
- Base Catalog release
- sha256:5082ec07047a2324648f569d234cc64342ce2707b2f3d77fde8fc06af517cee6