AI Readiness Audit
Ref. APM-C19B0A5E · Confidential

Control API v1

An independent assessment of whether the Control API v1 specification is ready for AI-assisted integration and autonomous agents, prepared for Ably Control.

Prepared for
Ably Control
Subject
Control API v1 v1.0.14
Scope
22 operations · 4 pillars · 3 groups
Date
September 2026
47/100
Not ready
Functional for AI-assisted builds.
Not ready for autonomous agents.
Reach AI-ready by Phase 2; resolve all findings → 100 · AI-ready
Import blocked: SDK, docs, and MCP generators will refuse this spec

The validation engine found 1 blocking violation: A discriminator cannot be present in a `oneOf` schema containing primitive type case(s).. Import tools reject the specification outright until it is fixed, so nothing downstream can be generated regardless of the other pillar scores. While this gate is open, the Standards Compliance score is capped at 40 and every AI pillar weights standards at 60% (normally 30%). Fixing the blocker in Phase 1 lifts the caps; the score projection below shows what that unlocks.

1
Critical blocker stopping entire operation groups for agents
1068
Total instances: 1 critical, 92 high, 305 medium, 670 low
31
Rule groups across 4 pillars: 1 critical, 92 high sev. instances
Executive summary

Your specification currently fails import: blocking violations make SDK, docs, and MCP generators refuse it, and the scores below are capped until they are fixed. Control API v1 scores 47.4/100: Not ready · Grade F. The weakest pillar is Standards compliance at 40; the strongest is SDK readiness for AI at 57. We recorded 1068 finding instances: 1 critical, 92 high, 305 medium, and 670 low. Functional for AI-assisted builds. Not ready for autonomous agents. Every finding lives in the specification, and the roadmap in this report orders the fixes by impact; resolving them projects the score to 100/100.

Readiness by pillar
Not ready 47 / 100
FoundationThe spec itself
40/100
Standards Compliancecapped · import blocked
OpenAPI validity, structural correctness, specification conformance, and import linting: can machines trust your spec?
40Not ready
Build Time ReadinessAI writes the code
52/100
Documentation Readiness for AI
Descriptions that say when to use an operation, examples that pin down every shape: whether an AI can learn the truth of your API from what you publish
47Not ready
SDK Readiness for AI
Clean types, predictable naming, correct formats: whether production-grade client code can be generated from your spec, by SDK pipelines and AI coding assistants alike
57Significant gaps
Runtime ReadinessAgents make the calls
49/100
MCP Readiness
Whether your operations survive being turned into tools: distinct names, descriptions that carry what an agent must know, safe invocation semantics, auth, error recovery, and context budget
49Not ready
Score projection · what fixing each phase unlocks
Todaycurrent score
47
Not ready
Phase 1fix criticals
62
Significant gaps
Phase 2+ fix highs
92
AI-ready
Phase 3+ fix mediums & lows
100
AI-ready
About this report. We evaluated the Control API v1 specification against thousands of deterministic rules we have refined over twelve years of building API tooling, supplemented by AI-based analysis. Every finding is reproducible from the spec itself, scored consistently, and paired with a concrete fix.
What's at stake

What these gaps cost you in production

4 failure modes across 3 groups, each driven by your audit scores. Several are active risks today.

Foundation The spec itself 40 / 100
Active risk · Standards compliance
Your spec breaks before code is even written
5 critical/high finding group(s) in this area. Score: 40/100.
22→29
code quality score out of 40: the lift consumers achieve when the underlying spec is clean and standards-compliant
APIMatic Context Plugins research · Series B · June 2026
Build Time Readiness AI writes the code 52 / 100
Active risk · Documentation readiness for AI
AI readers can't learn the truth of your API
1 critical/high finding group(s) in this area. Score: 47/100.
74%
of developers name missing or unclear documentation as the top reason they abandon an API. AI readers are stricter: what a human would ask about, an AI assumes.
APIMatic Developer Experience research · June 2026
Elevated risk · SDK readiness for AI
AI-built integrations ship with guessed assumptions
1 critical/high finding group(s) in this area. Score: 57/100.
0
fabricated API constructs when a coding assistant was grounded in an AI-ready spec. Ambiguity in the spec is what triggers hallucinated integration code
APIMatic Context Plugins research · 6 APIs · 3 models · June 2026
Runtime Readiness Agents make the calls 49 / 100
Active risk · MCP readiness
Autonomous agents can't safely operate your API
2 critical/high finding group(s) in this area. Score: 49/100.
65%
reduction in token consumption when agent tools are grounded in authoritative API context. Bloated or confusable tools consume up to 3.3× more.
APIMatic Context Plugins research · Series A · June 2026
The evidence numbers come from our controlled research: 6 experiments across 3 models, 6 commercial APIs, and 3 languages. We derive each card's risk status from this API's pillar scores. Full methodology at apimatic.io.
Contents

What's inside the full report

Unlock the full report

See all 4 pillar breakdowns, every finding with its fix, and the prioritized remediation roadmap.

Book a FREE audit to view this report