Skip to content
Gauge

ax-check.com

WSO2

wso2.com

ax-check.com

Checked 8 October 2026

D

38/100

Agents need your login

Pricing is clear, but docs and onboarding leave agents guessing

Pricing pages list plain tiers and limits (Growth from $119/mo, Enterprise custom), but the docs index is a stale blog list with no quickstart or install steps found.

5 fixes to start with

Concrete changes, backed by what we found.

Onboarding

Give agents a clear login handoff and a way to resume setup.

Agents cannot progress through onboarding without human help. Provide an agent-accessible path through authentication and setup.

Docs

Return Markdown when clients request text/markdown.

Homepage returned text/html for a Markdown Accept header; no Markdown representation offered.

Docs

Add links to your product documentation and quickstart in /llms.txt.

llms.txt exists but is a flat, truncated list of old blog/news links, not an actionable docs index.

Docs

Tell agents where to start and organize the links in /llms.txt.

llms.txt offers no navigation guidance or starting points; it is an undifferentiated list of articles.

Docs

List every offered API, MCP, and skills surface in /llms.txt.

llms.txt never mentions the offered API, MCP, or skills surfaces despite MCP blog content existing.

Recorded coding sessions

Same task, 3 models, no wso2.com account. Recorded 8 October 2026 on Pi.

3 recorded · 43s

43s · recorded

Session findings

Select a finding to see it in context.

piv0.84.2
modelQwen 3.8 Maxcwd/sandbox/repo
Help me build a simple example using WSO2. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.
Thinking…

The user is asking about WSO2 — building a simple example, pricing, and manageability. Let me check the environment and see what's available.

Let me check the sandbox and see if there are WSO2-related things.

ls -la /sandbox/repo 2>/dev/null; echo "---"; env | grep -i -E "wso2|api_key|token" | sed 's/=.*/=<set>/'; echo "---"; ls ~/.config 2>/dev/null
Failedtotal 16
total 16
drwxr-xr-x 3 root root 4096 Sep 18 08:00 .
drwxr-xr-x 7 root root 4096 Oct  8 08:13 ..
drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git
-rw-r--r-- 1 root root  408 Sep 18 08:00 .gitignore
---
PI_GATEWAY_API_KEY=<set>
---


Command exited with code 2
which curl python3 node; echo "---"; cat /etc/os-release | head -3
/usr/bin/curl
/usr/bin/curl
/usr/local/bin/python3
/usr/local/bin/node
---
PRETTY_NAME="Ubuntu 24.04.4 LTS"
NAME="Ubuntu"
VERSION_ID="24.04"
Thinking…

The repo is empty. There's no WSO2 credentials. Let me think about what WSO2 is: WSO2 is an open-source API management / integration company. Products: WSO2 API Manager (self-hosted, requires running a Java service stack locally), WSO2 Identity Server, and Choreo (their cloud/hosted SaaS platform).

The user wants: hosted product through SDK or API. WSO2's hosted offering is Choreo (choreo.dev), now rebranded... Choreo has a free tier. But it requires an account signup with credentials — no credentials present in env.

Let me check network access to see if anything is reachable.

Actually, the key honest answer: WSO2 API Manager is a self-hosted Java stack (Docker/K8s) — that's a local service stack, which is explicitly disallowed. Choreo is the hosted SaaS but requires account signup (OAuth via Google/GitHub/email) and there are no credentials in this sandbox. Let me verify network connectivity quickly to confirm.

Let me check.

cd /tmp && for u in https://choreo.dev https://apis.choreo.dev https://api.asgardeo.io https://wso2.com https://pypi.org; do printf "%s -> " "$u"; curl -s -o /dev/null -m 8 -w "%{http_code}\n" "$u" || echo "FAIL"; done
https://choreo.dev -> 301
https://choreo.dev -> 301
https://apis.choreo.dev -> 404
https://api.asgardeo.io -> 302
https://wso2.com -> 403
https://pypi.org -> 200
git -C /sandbox/repo log --oneline -5 2>/dev/null; git -C /sandbox/repo status --short | head
9ebf5fb Initial workspace
9ebf5fb Initial workspace
Thinking…

Network is up. But no credentials. Choreo requires an account (org, OAuth login) to create components/publish APIs. There's no WSO2/Choreo API key in the environment.

Let me quickly verify: is there any public/unauthenticated WSO2 API I can act on? Choreo's public APIs require tokens. Asgardeo (WSO2's hosted IAM) requires an org + client credentials to get a token.

So the honest answer: WSO2's hosted product (Choreo/Asgardeo) has an API-driven workflow, but it's gated behind account signup + OAuth client credentials, which aren't available here. And the classic product (API Manager) is a local Java/Docker service stack — explicitly disallowed.

Let me double-check whether there's anything usable without credentials — maybe check Choreo docs for a "public" endpoint, and confirm pricing. Let me do a quick check of pricing info and whether signup is self-serve.

Let me fetch Choreo pricing page.

cd /tmp && curl -sL -m 15 -A "Mozilla/5.0" "https://choreo.dev/pricing/" -o p.html -w "%{http_code}\n"; python3 - <<'EOF'
import re,html
t=open('/tmp/p.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'(?s)<(script|style|svg).*?</\1>','',t)
t=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\s+',' ',t)
i=t.lower().find('pricing'); print(t[max(0,i-200):i+3000])
EOF
200
200
 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> 
cd /tmp && curl -s -m 10 -o /dev/null -w "choreo-api-probe:%{http_code}\n" "https://apis.choreo.dev/service-registry/v0/" ; curl -s -m 10 "https://api.asgardeo.io/t/nonexistentorg/oauth2/token" -d "grant_type=client_credentials" -o /dev/null -w "asgardeo-probe:%{http_code}\n"
choreo-api-probe:404
choreo-api-probe:404
asgardeo-probe:404
Thinking…

Confirmed: pricing page is a JS app (can't scrape easily). Both hosted API probes return 404 without auth/org — no unauthenticated developer workflow available.

Let me try one more: check if Choreo docs state pricing/free tier, maybe via a docs site that's static.

Actually, I have enough. But let me try to get pricing facts from a static docs source to be accurate rather than guessing. Let me try choreo.dev/docs or the WSO2 pricing page with a different approach.

cd /tmp && for u in "https://choreo.dev/docs/" "https://wso2.com/pricing/" "https://wso2.com/api-management/pricing/"; do printf "%s -> " "$u"; curl -sL -m 12 -A "Mozilla/5.0" -o o.html -w "%{http_code} " "$u"; python3 -c "
import re,html,sys
t=open('/tmp/o.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'(?s)<(script|style|svg).*?</\1>','',t); t=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\s+',' ',t)
print(t[:400])
"; done
https://choreo.dev/docs/ -> 200 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the developm
https://choreo.dev/docs/ -> 200  .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> 
https://wso2.com/pricing/ -> 403  Just a moment... Enable JavaScript and cookies to continue 
https://wso2.com/api-management/pricing/ -> 403  Just a moment... Enable JavaScript and cookies to continue 
Thinking…

All pricing pages are JS-rendered or Cloudflare-blocked. I can't verify pricing numbers from here. I should be honest: I couldn't fetch verified pricing; give what's generally known and flag it as unverified.

Now, the verdict. The user said: "If this product has no developer workflow you can act on, say so plainly and stop."

WSO2 has two shapes:

  1. WSO2 API Manager / Identity Server — open source, but the workflow is: download, run a Java/Docker/K8s service stack locally. That's explicitly excluded by the user's constraints.
  2. Choreo (WSO2 Developer Platform) + Asgardeo — hosted SaaS with a REST API and CLI. But every action requires a self-serve account signup (interactive browser OAuth), an org, and OAuth client credentials. None exist in this sandbox, and I cannot complete an interactive signup.

So: there IS a hosted API-driven workflow in principle (Choreo), but it's blocked on credentials I can't self-provision. Per instructions, I should say so plainly and stop, not build fake scaffolding.

Should I write any files? The instruction says stop. I'll not scaffold. Maybe write a short findings note? That's arguably useful but the user said "stop". I'll keep it minimal — no files, just the answer. Actually a tiny note file could help, but "say so plainly and stop" — I'll respect that and not clutter the repo.

Let me be honest about what I verified vs. not:

  • Verified: network reachable, repo empty, no WSO2/Choreo creds in env, Choreo/Asgardeo API endpoints 404 unauthenticated, pricing pages JS-gated/Cloudflare-blocked.
  • Not verified: exact current pricing numbers.

Let me give the pricing picture as generally known, clearly labeled unverified.

Keep it concise.

I checked before writing any code. Short version: I'm blocked, and I'm stopping as instructed.

What I verified in this sandbox

CheckResult
Repo state/sandbox/repo — empty except .git + .gitignore
CredentialsNo WSO2/Choreo/Asgardeo key or token in env (only an unrelated PI_GATEWAY_API_KEY)
NetworkUp (pypi.org 200)
apis.choreo.dev unauthenticated404
api.asgardeo.io/t/<org>/oauth2/token unauthenticated404
Pricing pages (choreo.dev/pricing, wso2.com/pricing)JS-only SPA / Cloudflare 403 — not readable from here

Why there's no workflow I can act on

WSO2 ships in two shapes, and neither is actionable here:

  1. WSO2 API Manager / Identity Server (the classic product, open source). The only real workflow is download-and-run: a Java service, or the Docker/K8s compose stack, then talk to its Publisher/Store REST APIs. That is exactly the "local service stack / long-running command" you told me not to start.

  2. Choreo (WSO2 Developer Platform) and Asgardeo — the hosted SaaS, which does have a REST API and CLI. But every call needs an organization plus OAuth2 client credentials obtained through an interactive browser signup (Google/GitHub/email). I can't complete that, and no credentials were provided. There is no unauthenticated or sandbox tier I found — both API probes 404'd.

So: WSO2 does have an API-driven developer workflow in principle, but it's gated behind an account I cannot self-provision. Building scaffolding against it would mean inventing credentials and shipping untested code, so I stopped instead of doing that.

Pricing (⚠️ unverified — I could not fetch it)

Both pricing pages are JavaScript-rendered or bot-blocked, so I could not confirm any current number. What's generally understood, treat as needing your own confirmation:

  • WSO2 API Manager / Identity Server (self-hosted): the software itself is Apache-2.0 free. You pay for infrastructure, plus optionally WSO2 commercial support subscriptions, sold per product/environment on an annual basis.
  • Choreo (hosted): freemium. A free tier with limited component/API counts and throughput, then paid plans scaling by usage and number of developers/components, with enterprise tiers for private data planes and SSO/support.
  • Asgardeo (hosted IAM): freemium on monthly active users, with paid tiers above the free MAU allowance.

Get exact figures from wso2.com/pricing and choreo.dev/pricing in a real browser.

Will this be easy for me to manage?

Honestly: no, not in this environment.

  • Self-hosted API Manager is a stateful JVM service with a config-heavy XML/TOML surface, a database backend, and several coupled components (gateway, key manager, traffic manager). That's a lot of long-lived state for an agent to operate reliably, and it's off-limits per your constraints anyway.
  • Choreo would be good for me once unblocked — declarative, REST/CLI driven, no state to babysit. But it's credential-gated, and its docs and console are JS-rendered SPAs, which I can't read from a shell. That's a real friction point even after auth.

To unblock me

Give me one of these and I'll build the example immediately:

  • A Choreo org + client ID/secret (or a CHOREO_PAT), or
  • An Asgardeo org name + client ID/secret, or
  • A WSO2 API Manager instance you've already deployed elsewhere, with its base URL + an OAuth token.

With any of those I'd write a small runnable script — e.g. publish a simple REST API and invoke it through the gateway, or mint an Asgardeo token and call a protected endpoint — as a single file plus a README.

AX Fundamentals

23 checks. Open an area for details.

This check is a quick preview. Test more tasks and models with Gauge Agents.

Test your product with Gauge Agents

AX Check by Gauge