Evidence
observed · not disputed
Coverage
complete · 16/16 graded0/5 barrier checks verified
Freshness
fresh
Last tested
Revision
sha256:3ad3b06484df…

Agent report card

Can an agent use OpenRouter API through Model access lifecycle?

Grade B+: Safe failure handling is documented only partially.

OpenRouter / active

Agent ReadinessB+Limited

Five-stage assessment

Where agent autonomy holds and where it breaks

Five states · each from its own evidence · lifecycle order, not a journey
  1. EvaluateReady
  2. Sign upReady
  3. PayReady
  4. ProvisionReady
  5. OperateLimited
  1. 01

    Evaluate

    Ready

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    Applicable terms are stable, readable, retrievable, and materially complete.

    Eligibility conditions and required inputs are explicit and decidable.

    Price or no-charge status, variables, currency, and material conditions are explicit.

    Verified structured artifacts accelerate discovery of the evaluation surface.

    Web-agent access policy is explicit and verified for the assessed resources.

    Evidence and actions6 signals

    Can an agent decide every material eligibility condition before commitment?

    supported: fresh

    Eligibility conditions and required inputs are explicit and decidable.

    OpenRouter explicitly defines its eligibility criteria: users must be at least 13 years old (with parent/guardian permission if under 18) and must warrant compliance with laws, non-suspension, and organizational binding authority.

    eligibility_decidability: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent estimate cost or confirm no-charge status before commitment?

    supported: fresh

    Price or no-charge status, variables, currency, and material conditions are explicit.

    OpenRouter defines US dollars as its base currency, describes pass-through inference pricing, and discloses credit-purchase and BYOK fees.

    pricing_decidability: Ready: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent find the exact service and its stable entrypoints?

    supported: fresh

    The exact service and stable evaluation or access entrypoints are publicly discoverable.

    OpenRouter's stable entrypoints and API endpoints (such as https://openrouter.ai/api/v1/chat/completions) are publicly documented and discoverable in the quickstart and llms.txt index.

    service_discovery: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are verified structured discovery artifacts available?

    supported: fresh

    Verified structured artifacts accelerate discovery of the evaluation surface.

    Verified structured discovery artifacts including /llms.txt and /openapi.json are publicly available to accelerate machine evaluation of OpenRouter services.

    structured_evaluation_discovery: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent retrieve and understand the applicable commitment terms?

    supported: fresh

    Applicable terms are stable, readable, retrievable, and materially complete.

    OpenRouter's Terms of Service are stable, retrievable, and materially complete at https://openrouter.ai/terms.

    terms_access: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Does the vendor deliberately describe access for web agents?

    supported: fresh

    Web-agent access policy is explicit and verified for the assessed resources.

    OpenRouter explicitly publishes a robots.txt policy that sets User-Agent: * with Disallow: /seo/ and allows access to other public resources.

    verified_web_agent_access: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

  2. 02

    Sign up

    Ready

    A stable canonical route begins the required access bootstrap.

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    Evidence and actions5 signals

    Can an agent operate the access controls and safe handoffs deterministically?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The retained sign-up page capture displays an email verification requirement error message ('We could not find a primary email address on your account. Please contact support.') and does not establish machine operability of access controls or safe handoffs.

    access_control_operability: Unknown: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Is there a stable route to begin obtaining service access?

    supported: fresh

    A stable canonical route begins the required access bootstrap.

    OpenRouter provides a stable canonical entrypoint for account creation at https://openrouter.ai/sign-up.

    access_entrypoint_stability: Ready: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain access without an unsupported CAPTCHA boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    Across all evaluated surfaces, the retained evidence does not explicitly declare the presence or absence of a mandatory CAPTCHA challenge.

    captcha_compatible_access: Unknown: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent obtain scoped, revocable authority for this service?

    supported: fresh

    Scoped revocable credentials or delegated authorization have explicit consent and resumption boundaries.

    OpenRouter provides delegated authorization and scoped credentials via OAuth PKCE, where an app sends a user to /auth to authorize and exchanges the code at /api/v1/auth/keys for a user-controlled API key.

    delegated_identity_access: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can required phone verification be completed through a supported boundary?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    Current admissible evidence does not explicitly address phone verification requirements.

    phone_verification_compatible: Unknown: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

  3. 03

    Pay

    Ready

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    A documented direct purchase path reaches paid access without a vendor decision point.

    Evidence and actions4 signals

    Can an agent construct checkout, hand off approval safely, and resume?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The retained evidence describes credit purchases, manual top ups, and auto top ups, but does not provide details on deterministic checkout construction, approval handoff, or resumption by an agent.

    checkout_operability: Unknown: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Is the exact commercial commitment disclosed before authorization?

    supported: fresh

    Charge or no-charge status, currency, recurrence, and material conditions are disclosed.

    OpenRouter discloses US dollars as its base currency, explains pass-through inference pricing, and states a 5.5% credit-purchase fee with an $0.80 minimum.

    commitment_disclosure: Ready: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can payment be authorized within scoped agent or explicit human authority?

    supported: fresh

    Current admissible evidence does not resolve this finding.

    The evidence lists supported payment methods including major credit cards, AliPay, and USDC cryptocurrency, but does not document a scoped delegation framework or explicit human-authorization protocol with receipts for payment authorization.

    payment_authorization: Unknown: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Is a direct self-service path to paid access documented?

    supported: fresh

    A documented direct purchase path reaches paid access without a vendor decision point.

    Users can get started by creating an account and adding credits directly on the Credits page via manual top up or auto top up without requiring a vendor decision point or sales interaction.

    self_service_purchase: Ready: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

  4. 04

    Provision

    Ready

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    Evidence and actions3 signals

    Can usable access material be delivered securely to an authorized agent?

    supported: fresh

    Credentials, grants, or configuration are delivered through a documented agent-usable flow.

    OpenRouter API key creation returns the plaintext key in the response payload when created via the POST /api/v1/keys management endpoint. The key string is returned directly in the response payload as a write-only value.

    access_material_delivery: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent determine successful provisioning completion and reconcile asynchronous failure?

    supported: fresh

    A synchronous success response returns a usable created resource or access material; otherwise asynchronous work exposes progress, terminal state, reconciliation, and a documented bound.

    API key creation is synchronous and returns a 201 Created HTTP response with the usable API key data object containing the plaintext key, ID, workspace, and usage limits upon success.

    provisioning_completion: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can provisioning be initiated within supported agent authority?

    supported: fresh

    Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

    API key provisioning is machine-triggerable via a POST request to https://openrouter.ai/api/v1/keys using a management Bearer token.

    provisioning_operability: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

  5. 05

    Operate

    Limited

    Safe failure handling is documented only partially.

    Only part of the credential lifecycle is agent-operable.

    Every essential target has a stable documented agent-usable interface alternative.

    Request-time authentication is documented and usable under scoped agent authority.

    Essential operations have stable readable request, response, and effect semantics.

    A verified agent-native interface covers the declared assessment targets.

    Evidence and actions6 signals

    Is an agent-native protocol interface verified against the essential targets?

    supported: fresh

    A verified agent-native interface covers the declared assessment targets.

    OpenRouter explicitly provides an MCP server interface that connects AI tools over the Model Context Protocol, allowing assistants to query live model, credit, and ranking data, as well as execute tool calls.

    agent_protocol_interface: Ready: tested 21 Aug

    • inference-api
    • model-catalog-api
    • openrouter-mcp

    Method public-http-semantic-assessment 2026-08-20

    Can an agent manage credential expiry, rotation, revocation, compromise, and recovery?

    supported: fresh

    Only part of the credential lifecycle is agent-operable.

    OpenRouter documents programmatic API-key creation, listing, update, and deletion, including expiry and limit controls. The retained evidence does not establish automated compromise recovery.

    credential_lifecycle: Limited: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Can an agent handle applicable failure modes safely?

    supported: fresh

    Safe failure handling is documented only partially.

    Retained documentation establishes authentication errors, rate-limit and credit-limit handling, and support escalation, but does not establish idempotency, cancellation, or reconciliation semantics.

    failure_contract: Limited: tested 21 Aug

    Method bounded-headless-semantic-assessment 2026-08-20

    Can an agent authenticate service operations with scoped authority?

    supported: fresh

    Request-time authentication is documented and usable under scoped agent authority.

    OpenRouter documents request-time authentication via Bearer tokens in the Authorization header, supporting both standard API keys and management API keys for restricted operations.

    operation_authentication: Ready: tested 21 Aug

    Method public-http-semantic-assessment 2026-08-20

    Are essential operation inputs, outputs, and effects stable and decidable?

    supported: fresh

    Essential operations have stable readable request, response, and effect semantics.

    Every essential target endpoint specifies stable readable schemas, request parameters, response fields, and error shapes across standard HTTP and SSE streaming interfaces.

    operation_contract: Ready: tested 21 Aug

    • inference-api
    • model-catalog-api
    • openrouter-mcp

    Method public-http-semantic-assessment 2026-08-20

    Can an agent perform every essential assessment target through a usable interface?

    supported: fresh

    Every essential target has a stable documented agent-usable interface alternative.

    All essential assessment targets provide machine-operable API interfaces or standard structured JSON/OpenAPI endpoints for programmatic interaction.

    target_interface_access: Ready: tested 21 Aug

    • inference-api
    • model-catalog-api
    • openrouter-mcp

    Method public-http-semantic-assessment 2026-08-20

    What would improve this stage

    • Document applicable structured errors, retry, cancellation, and reconciliation semantics.
    • Provide scoped expiry, rotation, revocation, compromise, and recovery operations.

What works

  • Evaluate: The exact service and stable evaluation or access entrypoints are publicly discoverable.
  • Sign up: A stable canonical route begins the required access bootstrap.
  • Pay: Charge or no-charge status, currency, recurrence, and material conditions are disclosed.
  • Provision: Provisioning is machine-triggerable or follows deterministically from an allowed handoff.

What blocks agents

  • Operate: Safe failure handling is documented only partially.

Startup offers

OpenRouter on the startup-offers board

catalog record →

Improve the report

Correct it, rerun it, or improve the funnel.

Profile
arp_01m0j1a50vat933f76xwy3mec5
Projection
sha256:53292bcbc365d31557093d4fb9d1772b224412157c14958543e4d6f9036244d4
Policy
service-use-2026-08-20-public-evidence-r9 · sha256:57bf95fd6d0fe6fe9173a68b60e8d8dc2179b357c88ff4349675a72d0e1d4139