# AX Check: wso2.com
Checked 2026-10-08.

Pricing is clear, but docs and onboarding leave agents guessing
Pricing pages list plain tiers and limits (Growth from $119/mo, Enterprise custom), but the docs index is a stale blog list with no quickstart or install steps found.

## Onboarding needs a login

## Coding sessions
All three independent sessions completed and reported on pricing using live pricing pages, citing tiers like free trials, usage-based plans, and custom enterprise quotes, though one flagged its own figures as unverified.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/b048542e-1e1b-43ff-bfa4-f61566d1420d) · [Read transcript](https://www.ax-check.com/wso2.com/sessions/deepseek.json)
Final output gives concrete tiers (Free $0/15k MAUs, Growth from $25/mo capped at $2000, Enterprise custom; Choreo Developer $0+credits, Team $150/component/mo) sourced from live pricing pages fetched at seq 100-103, with plan/usage assumptions named.
#### End-to-end onboarding
- **End-to-end onboarding not demonstrated**: The agent never obtained real product credentials (no WSO2/Asgardeo organization signup, no client ID) and never performed an authenticated operation against the hosted service. It only fetched public docs/npm packages, scaffolded a static React app with placeholder env values, and ran a local `npm run build` that produces a static bundle without any network call to Asgardeo. No login or API call against the hosted product occurred.
  Event 106:

  ```text
  Interactive login** needs a real WSO2 organization + registered app
    (email/browser signup), which this environment does not have.
  ```
  Event 96:

  ```text
  ✓ 227 modules transformed.
  rendering chunks...
  computing gzip size...
  dist/index.html                   0.41 kB
  ```
  Event 77:

  ```text
  VITE_ASGARDEO_CLIENT_ID=<your-app-client-id>
  VITE_ASGARDEO_BASE_URL=https://api.asgardeo.io/t/<your-organization-name>
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to create a WSO2 tenant/app from the CLI**: Registering an Asgardeo/WSO2 Identity Platform organization and a Single Page Application (to obtain a client ID) requires browser-based signup and console interaction. This is normal product authentication design, not a defect, but it stopped the agent from running a real login round-trip in this headless session.
  Event 106:

  ```text
  Interactive login** needs a real WSO2 tenant.** Creating the organization and registering a Single Page Application requires email/browser signup and a dashboard — I can't do that here, and I have no client ID.
  ```
- **Quickstart's final verification step requires a long-running dev server**: The official React quickstart's last step is `npm run dev`, a long-running local server. Per the session's explicit instruction to avoid long-running commands, the agent stopped after a static `npm run build` instead of exercising the actual sign-in flow. This is a test-environment restriction self-imposed by instruction, not a product flaw.
  Event 111:

  ```text
  The quickstart's final step is `npm run dev` — a long-running local dev server. Per your instruction I did not start it. I stopped at the static `npm run build`, which is the furthest a headless environment can honestly go.
  ```

#### Suggested Changes
- **Add a CLI/API path for creating a trial organization and SPA client ID**: On the WSO2 Identity Platform / Asgardeo quickstart (wso2.com/asgardeo/docs/quick-starts/react/), provide a scriptable way (CLI command or REST call with an API key) to provision a trial org and register a Single Page Application, so a client ID/base URL can be obtained without browser-based signup. Verify by confirming an agent can run one command and receive a working clientId/baseUrl pair usable in AsgardeoProvider without opening a browser.
  Event 63:

  ```text
  Configure an Application in WSO2 Identity Platform Create a React app using Vite Install @asgardeo/react Add <AsgardeoProvider /> to your app Add sign-in and sign-out to your app Display signed-in user's profile information Run the app
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/2cb0d33d-e223-476a-8071-2ebab378fd2e) · [Read transcript](https://www.ax-check.com/wso2.com/sessions/kimi.json)
seq 6/17 give cost structure with named assumptions: self-hosted is Apache 2.0 free (support quote-based), Asgardeo free tier then paid scaling by MAU, Choreo free tier + pay-as-you-go, while flagging to check current pricing pages for exact figures.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained real Asgardeo credentials itself. It wrote a script that requires a human to sign up in the Asgardeo console, create an app, and paste in client ID/secret. The script was only run once, and it exited immediately because no .env file with credentials existed. No API call was ever made to the actual hosted Asgardeo service.
  Event 16:

  ```text
  Missing config. Copy .env.example to .env and fill in ASGARDEO_ORG,
  ASGARDEO_CLIENT_ID, and ASGARDEO_CLIENT_SECRET from the Asgardeo console.
  exit=1
  
  ```
  Event 17:

  ```text
  the script is ready and syntax/runtime-verified up to the auth step, but I can't execute the real API calls without Asgardeo credentials you create in the console
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to get Asgardeo credentials**: Asgardeo requires a human to sign up via its hosted console and manually create an app, enable the client-credentials grant, and copy a client ID/secret. This is normal product behavior (a standard auth onboarding flow) rather than a defect, but it stopped the agent from completing any authenticated API call in this session.
  Event 6:

  ```text
  I'll build the example against **Asgardeo**, since it has a clean REST/OIDC workflow with zero local infrastructure.
  ```
  Event 17:

  ```text
  I can't execute the real API calls without Asgardeo credentials you create in the console. That signup takes ~2 minutes and is free.
  ```

#### Suggested Changes
None identified in this transcript.

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/0a0d8d23-a1bc-402e-8340-f921404a5221) · [Read transcript](https://www.ax-check.com/wso2.com/sessions/qwen.json)
Final output gives pricing structure per product (self-hosted free+support subscriptions, Choreo/Asgardeo freemium-by-usage) while explicitly flagging it as '⚠️ unverified' because pricing pages were JS-only/bot-blocked (seq 26, final output).
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained WSO2/Choreo/Asgardeo credentials. It searched the sandbox environment for API keys and found none, then probed the hosted Choreo and Asgardeo APIs unauthenticated, both returning 404. It concluded that any real workflow requires an interactive browser signup (OAuth2 client credentials via Choreo/Asgardeo) that it cannot self-provision, and stopped without performing any authenticated operation.
  Event 6:

  ```text
  PI_GATEWAY_API_KEY=<set>
  ```
  Event 21:

  ```text
  choreo-api-probe:404
  asgardeo-probe:404
  
  ```
  Event 27:

  ```text
  every call needs an organization plus OAuth2 client credentials obtained through an **interactive browser signup** (Google/GitHub/email). I can't complete that, and no credentials were provided.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service credentials for Choreo or Asgardeo**: The agent found no WSO2/Choreo/Asgardeo API key in the sandbox environment and could not find an unauthenticated or sandbox tier for either hosted API. Both probed endpoints returned 404 without credentials. This is a missing-credentials blocker inherent to the product's signup flow (interactive browser-based OAuth signup), not a product defect or agent error.
  Event 6:

  ```text
  PI_GATEWAY_API_KEY=<set>
  ```
  Event 21:

  ```text
  choreo-api-probe:404
  asgardeo-probe:404
  
  ```
  Event 27:

  ```text
  No WSO2/Choreo/Asgardeo key or token in env (only an unrelated `PI_GATEWAY_API_KEY`)
  ```
- **Pricing pages unreadable from a shell session**: wso2.com/pricing pages returned HTTP 403 behind a Cloudflare JavaScript challenge, and choreo.dev pages are a client-rendered SPA requiring JavaScript, so curl-based fetches returned only placeholder content instead of pricing figures. This is a test-environment limitation (no browser/JS execution available) rather than a product defect.
  Event 25:

  ```text
  https://wso2.com/pricing/ -> 403  Just a moment... Enable JavaScript and cookies to continue
  ```
  Event 20:

  ```text
  200
   .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app.
  ```
- **Self-hosted WSO2 product excluded by session constraints**: The only non-gated WSO2 workflow identified was the self-hosted API Manager/Identity Server, which requires running a Java service or Docker/K8s stack long-term. The seed prompt explicitly forbade starting local service stacks or waiting on long-running commands, so the agent correctly ruled this path out rather than attempting it.
  Event 27:

  ```text
  That is exactly the "local service stack / long-running command" you told me not to start.
  ```

#### Suggested Changes
- **Add a server-rendered or documented pricing page accessible without JavaScript**: Both wso2.com/pricing and choreo.dev/pricing could not be read via a plain HTTP fetch: wso2.com returned a Cloudflare JS-challenge 403 and choreo.dev returned an empty SPA shell. Publishing a static HTML/text fallback (or a plain-text pricing doc) would let automated tools and low-bandwidth users verify pricing without a full browser. Verify by curling the page with a generic user agent and confirming pricing text appears in the raw HTML.
  Event 25:

  ```text
  https://wso2.com/pricing/ -> 403  Just a moment... Enable JavaScript and cookies to continue
  ```
  Event 20:

  ```text
  200
   .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app.
  ```
- **Offer a self-service API credential or sandbox tier for Choreo/Asgardeo**: Unauthenticated probes to apis.choreo.dev and api.asgardeo.io both returned 404 with no indication of how to obtain a trial/sandbox credential without an interactive browser signup. Adding a documented sandbox API key flow (e.g., a curl-able signup endpoint or clearly published trial credentials) would let non-interactive agents and CI tools exercise the hosted API. Verify by confirming a script can obtain a working token end-to-end without a browser.
  Event 21:

  ```text
  choreo-api-probe:404
  asgardeo-probe:404
  
  ```

### Task given to each agent
Help me build a simple example using WSO2. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: D · 38/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — Homepage answers Markdown requests

  ```text
  Homepage returned text/html for a Markdown Accept header; no Markdown representation offered.
  ```

- **Failed** — llms.txt provides an actionable documentation index

  ```text
  llms.txt exists but is a flat, truncated list of old blog/news links, not an actionable docs index.
  ```

- **Failed** — llms.txt provides navigation guidance

  ```text
  llms.txt offers no navigation guidance or starting points; it is an undifferentiated list of articles.
  ```

- **Failed** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt never mentions the offered API, MCP, or skills surfaces despite MCP blog content existing.
  ```

- **Failed** — A compact guide representation exists

  ```text
  llms.txt exists but is a flat, stale blog/news link dump, not a compact guide to docs or products.
  ```

- **Failed** — A focused guide is directly retrievable

  ```text
  No standalone Markdown guide is offered; homepage returns HTML even when Markdown is requested.
  ```

- **Skipped** — Equivalent instructions fit a token budget

  ```text
  No compact guide representation was fetched, so token budget cannot be measured.
  ```

- **Skipped** — Product-docs links survive format changes

  ```text
  Homepage Markdown is unsupported, so link preservation across formats cannot be judged.
  ```

- **Skipped** — The compact guide is independently actionable

  ```text
  No compact agent-specific guide was fetched; only marketing pages and an ebook landing page.
  ```

- **Skipped** — Install and next-step links resolve

  ```text
  No install or next-step link was fetched, so resolution cannot be judged.
  ```


### Onboarding
- **Skipped** — Docs lead to a relevant quickstart

  ```text
  Fetched pages are marketing ebooks and blog posts, not a product quickstart with first steps.
  ```

- **Skipped** — Installation commands are extractable

  ```text
  No installation or setup page for the subject product was fetched.
  ```

- **Skipped** — Code examples are available without interaction

  ```text
  Fetched pages show no code examples for the subject product.
  ```

- **Skipped** — Prerequisites and auth boundaries are explicit

  ```text
  No docs page stating prerequisites or auth boundaries was fetched.
  ```


### Pricing
- **Pass** — Pricing is readable without interaction

  ```text
  API Platform pricing page shows plans, prices and a calculator in plain HTML without interaction.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Prices stated: 30-Day Trial $0/mo, Growth from $119/mo, Enterprise custom.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Units explicit: managed interfaces, gateway events, API requests/month, builds, logs.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: Final output gives concrete tiers (Free $0/15k MAUs, Growth from $25/mo capped at $2000, Enterprise custom; Choreo Developer $0+credits, Team $150/component/mo) sourced from live pricing pages fetched at seq 100-103, with plan/usage assumptions named. Kimi K3: seq 6/17 give cost structure with named assumptions: self-hosted is Apache 2.0 free (support quote-based), Asgardeo free tier then paid scaling by MAU, Choreo free tier + pay-as-you-go, while flagging to check current pricing pages for exact figures. Qwen 3.8 Max: Final output gives pricing structure per product (self-hosted free+support subscriptions, Choreo/Asgardeo freemium-by-usage) while explicitly flagging it as '⚠️ unverified' because pricing pages were JS-only/bot-blocked (seq 26, final output). This behavioural item does not affect the fast grade.
  ```


### Activation
- **Skipped** — An API reference or OpenAPI spec is reachable

  ```text
  No fetched page shows an API reference or OpenAPI spec for WSO2's own developer APIs.
  ```

- **Pass** — An MCP server is documented and well-formed

  ```text
  Asgardeo MCP Server documented with quickstart, GitHub repo, and OAuth2 scoping details.
  ```

- **Pass** — A CLI install path is documented

  ```text
  Choreo CLI install script for Linux/macOS and PowerShell for Windows documented.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No registry lookup result for a WSO2 SDK or CLI package was supplied.
  ```

- **Skipped** — Agent skills are published

  ```text
  No agent skills surface is offered or documented in the fetched pages.
  ```



[Full report data](https://www.ax-check.com/wso2.com/report.json)
