Corbado
Powered by JAIRF v1.0.0 by Jentic · open methodology at /the-headless-index/methodology
Corbado earns Band C in the Auth & Identity category of The Headless Index, with a thesis-fit score of 50/100. Its strongest dimension is API-first design intent (14/20); its weakest scored dimension is MCP and agent posture (6/20). No public OpenAPI specification was found when Corbado was scored, which limits how far an agent can go without human integration work.
Scorecard detail
Corbado splits cleanly into a Backend API and a Frontend API, roughly forty-five and fifty-five documented operations respectively, covering passkeys, challenges, login identifiers and sessions. Server SDKs are maintained and reasonably popular for the size of the company (corbado-php at 115 stars, corbado-nodejs at 109, corbado-python at 85), with iOS, Android and Flutter clients alongside.
signals (6)
- +AI review appliedReviewer: Editorial review on 2026-08-19
- −OpenAPI specNot found across 34 probe paths
- −GraphQL endpointNot discovered (5 probes; project-scoped endpoints require a real project ID)
- +SDKs maintained4 (kotlin, python, swift, typescript); top by stars: corbado/corbado-python (85 stars)
- +SDK recency1 of 4 SDK repos pushed within 30 days (most recent SDK commit: 2026-08-05)
- −npm weekly downloadsNo published npm package detected for the JS/TS SDKs
cite (1)
- ai_review_browser.auth@2026-08-19
A CLI exists and is written in Go (github.com/corbado/cli), which is more than most passkey vendors offer, but it is small at eleven stars. Project and environment configuration lives in the developer panel: no Terraform provider is registered, and relying-party settings, UI component behaviour and Connect actions have no declarative representation an agent could diff.
signals (9)
- +AI review appliedReviewer: Editorial review on 2026-08-19
- −API operations exposedNo OpenAPI spec; operations count unknown
- ·Docs pages crawled0 pages (crawler: none)
- ·Auth schemes documentedAuth documentation page not reached by crawler
- ·Setup / quickstart docsNot reached by crawler
- ·Billing docsNot reached by crawler
- ·Teams / org docsNot reached by crawler
- ·CLI docsNot reached by crawler
- ·Schema / data model docsNot reached by crawler
cite (1)
- ai_review_browser.topics_found@2026-08-19
No MCP server exists under the org and the public registry returns nothing for Corbado. The one agent-facing gesture is an llms.txt on the docs site (docs.corbado.com/llms.txt), which is real but passive. For a vendor whose whole job is proving who a user is, having no callable identity tool for agents is a missed position.
signals (4)
- +AI review appliedReviewer: Editorial review on 2026-08-19
- −Official MCP serverNone found in vendor's GitHub org or the official MCP registry
- −Community MCP serversNone found
- +Agent-friendly SDKs1 TS/JS SDKs available; top: corbado/custom-api
cite (1)
- github.sdks@2026-08-19
The docs advertise a spec and then fail to serve it: the llms.txt index links an OpenAPI document that returns 404 (docs.corbado.com/api-reference/openapi.json). A spec clearly exists internally, since the org maintains a fork of oapi-codegen to generate its clients. Publishing the artifact it already builds would move this score a long way.
signals (3)
- +AI review appliedReviewer: Editorial review on 2026-08-19
- −OpenAPINot discovered across 34 standard probe paths
- −GraphQL introspectionNo GraphQL endpoint discovered (5 probes; some vendors use project-scoped endpoints that require a real project handle)
cite (1)
- ai_review_browser.schema@2026-08-19
There is no event catalogue to speak of. Corbado Connect documents actions as the extension point (docs.corbado.com/corbado-connect/architecture/actions), and that page is the only webhook mention in the entire docs index. No outbound event types, no signing scheme, no retry or replay semantics are published, so an agent watching for a new passkey enrolment must poll.
signals (2)
- +AI review appliedReviewer: Editorial review on 2026-08-19
- ·Webhook docs pageNot reached by crawler within budget (0 pages crawled). Cannot confirm whether vendor offers webhooks.
cite (1)
- ai_review_browser.pages_fetched@2026-08-19
This vendor does not publish a public OpenAPI specification. JAIRF cannot be computed. The Headless Index score and editorial verdict carry the readiness assessment.
No public OpenAPI specification discovered during collection
Powered by JAIRF v1.0.0 by Jentic
Band rationale:C band: scores 40-75 range
Show Corbado's score on your site.
Drop a live badge into your README, footer, or marketing page. It updates automatically when we re-score, and every embed is a dofollow link back here.
Corbado and agent readiness
- Is Corbado agent-ready?
- Corbado scores Band C on The Headless Index. Its JAIRF rating is not available because no machine-readable spec was scored. Its strongest area for agent use is API-first design intent; its weakest is MCP and agent posture.
- Does Corbado publish an OpenAPI spec?
- No published OpenAPI specification was found when Corbado was scored. That caps its JAIRF dimensions and forces agents to rely on documentation or reverse engineering to operate it.
- What is Corbado's Headless Index score?
- Corbado scores 50/100 on the Headless Index thesis-fit rubric and sits in Band C in the Auth & Identity category. The score weighs API-first design, headless operation, MCP and agent posture, schema observability, and webhooks.