Independent public observation · Agentic commerce · Wave 2
Is Carvana ready for AI agents?
A journey audit of www.carvana.com, measured against a fixed safe-stop task and supported by public scanner evidence.
CVNA · Observed Aug 27, 2026, 3:46 PM · Methodology 2026-08-23-v2
Publication state
Independent profile
Numeric ranking withheld pending owner opt-in
Evidence coverage
37%
Published strengths
6
Observed gaps
8
Fixed journey contract
- Goal
- Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment.
- Exact task
- Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification.
- Safe stopping point
- Stop before reserving a vehicle, starting financing or a credit check, submitting a trade-in, uploading identification, scheduling delivery, signing, or paying.
The scanner inspected public URLs and observable surfaces. It did not claim to complete this transaction, create an account, submit a lead, sign an agreement, or exercise authenticated product behavior.
Strengths
- web.robots-policy: robots.txt found — HTTP 200 AI agents are not explicitly blocked in robots.txt robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml
- web.llms-txt: llms.txt found — Quality: 3/3
- web.https: HTTP redirects to HTTPS
- web.security-headers: Content-Security-Policy present Frame embedding protection present X-Content-Type-Options nosniff present
- web.captcha: No obvious CAPTCHA detected
- web.secret-exposure: No obvious secrets detected in HTML
Failures and gaps
- Observation limitation (not a target failure): Playwright DOM audit unavailable: Verify the Browserless token and WebSocket endpoint to enable deep DOM + accessibility checks.
- Observation limitation (not a target failure): Playwright/browser compatibility checks skipped: Verify the Browserless token and WebSocket endpoint to enable real browser automation checks.
- web.sitemap-discovery: robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml sitemap.xml missing or invalid — https://www.carvana.com/sitemap.xml
- web.agent-instructions: Missing agent instructions (agents.md / AGENTS.md) — Add one to site or repo
- web.agent-card: No agent manifest found — Checked /.well-known/agent-card.json and ai-agent.json
- web.legal-trust: Privacy policy not verified — HTTP 403 Terms of service not verified — HTTP 403
- commerce.readiness: No machine-readable product feed found — Checked link rel=alternate + common paths
- 19 checks were unobservable; this limits conclusions about rendered interaction, accessibility, navigation, and task completion.
Observable evidence
These records reflect what the scanner could observe at the stated time. Missing access, bot defenses, geographic differences, authentication, or browser-provider failures reduce coverage rather than proving failure.
web.robots-policy
passrobots.txt found — HTTP 200 AI agents are not explicitly blocked in robots.txt robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml
web.sitemap-discovery
partialrobots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml sitemap.xml missing or invalid — https://www.carvana.com/sitemap.xml
web.llms-txt
passllms.txt found — Quality: 3/3
web.structured-data
unobservableNo direct evidence was observable in this scan.
web.navigation
unobservableNo direct evidence was observable in this scan.
web.form-labels
unobservableNo direct evidence was observable in this scan.
web.cta-discoverability
unobservableNo direct evidence was observable in this scan.
web.security-headers
passContent-Security-Policy present Frame embedding protection present X-Content-Type-Options nosniff present
web.legal-trust
failPrivacy policy not verified — HTTP 403 Terms of service not verified — HTTP 403
commerce.readiness
partialNo machine-readable product feed found — Checked link rel=alternate + common paths
Observation coverage: 37% · methodology: 2026-08-23-v2 · scanned 2026-08-27T20:46:39.693Z
Carvana’s online transaction scale makes it an important test of high-consideration agentic commerce. A usable public site is only the first layer; the decisive readiness questions concern vehicle provenance, financing disclosure, reservation state, and deliberate human confirmation.
This profile is an independent, evidence-limited diagnostic of the public website at `www.carvana.com`. It is not sponsored by or affiliated with Carvana. It is not a certification, accessibility determination, security audit, legal conclusion, endorsement, or claim that every browser agent can complete the task. Coverage is reported because a finding based on narrow observation is incomplete evidence.
The exact task and where the agent must stop
Goal: Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment.
Fixed task: Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification.
Safe stopping point: Stop before reserving a vehicle, starting financing or a credit check, submitting a trade-in, uploading identification, scheduling delivery, signing, or paying.
This boundary is part of the test, not a footnote. Agentic usability is not demonstrated by reaching the most consequential button quickly. It is demonstrated when the system can assemble a trustworthy preview, expose uncertainty and material terms, preserve user intent, and pause before an action that changes money, legal position, privacy, inventory, another person’s state, or production systems. For this commerce profile, that concrete boundary is: Stop before reserving a vehicle, starting financing or a credit check, submitting a trade-in, uploading identification, scheduling delivery, signing, or paying. The recorded scan did not execute the fixed task end to end; it gathered public technical evidence relevant to whether an agent could begin that journey. The editorial analysis maps that evidence to the declared task without claiming observations the scanner did not make.
What the scanner observed
The public Tier 1 scan used AgentReady methodology `2026-08-23-v2`, requested browser evidence, and included public protocol, content, security, legal-trust, and commerce probes where applicable. It returned 37% evidence coverage. Numeric diagnostic values are retained in the raw artifact and index metadata for auditability, but this editorial profile does not render or rank companies by them.
- web.robots-policy — pass. robots.txt found — HTTP 200 AI agents are not explicitly blocked in robots.txt robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml
- web.sitemap-discovery — partial. robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml sitemap.xml missing or invalid — https://www.carvana.com/sitemap.xml
- web.llms-txt — pass. llms.txt found — Quality: 3/3
- web.structured-data — unobservable. No direct evidence was observable in this scan.
- web.navigation — unobservable. No direct evidence was observable in this scan.
- web.form-labels — unobservable. No direct evidence was observable in this scan.
- web.cta-discoverability — unobservable. No direct evidence was observable in this scan.
- web.security-headers — pass. Content-Security-Policy present Frame embedding protection present X-Content-Type-Options nosniff present
- web.legal-trust — fail. Privacy policy not verified — HTTP 403 Terms of service not verified — HTTP 403
- commerce.readiness — partial. No machine-readable product feed found — Checked link rel=alternate + common paths
Observable evidence is intentionally phrased as what the scanner found at that timestamp. “Pass” does not prove that every route or personalized state shares the same behavior. “Unobservable” is not a target failure; it means the scan lacked enough evidence to evaluate the check. “Not applicable” means the optional surface was not positively observed. “Partial” means some useful evidence existed alongside a concrete gap.
Why Carvana belongs in the index
Carvana describes itself as an ecommerce platform where customers shop, sell, finance, and trade vehicles online, with delivery or pickup. It reported 197,325 retail units in the second quarter of 2026 and says more than four million customers have used its experience since launch. The combination of inventory turnover, credit, legal paperwork, logistics, and large transaction value creates a much higher consequence boundary than ordinary retail.
Carvana belongs in the index because “Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment” is a recognizable user outcome with a meaningful transition from information to action. That is more useful than a file-presence leaderboard: the question is whether the public evidence supports this particular journey. A site can publish `llms.txt` and still make price, authority, provenance, or confirmation ambiguous. Conversely, a site can lack an emerging convention and still provide strong semantic HTML and a safe human review boundary. This profile records both technical signals and the consequence model for find two used compact suvs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification.
The official sources cited below describe Carvana strategy and product claims; the primary context anchor is “Carvana announces record second quarter 2026 results.” Those claims are not treated as scanner evidence. Corporate announcements explain why this journey matters, while only the timestamped public scan supports the diagnostic observations in this profile. Product availability, regional scope, pricing, and authenticated behavior may differ from the public narrative and may change after publication.
Journey analysis: from discovery to a reviewed next step
The task limits the agent to research and comparison. An agent must timestamp inventory, identify which vehicle-history fields are first-party or third-party, distinguish advertised terms from individualized financing, and avoid presenting estimated payment as total affordability. Reservation can remove inventory from other shoppers and financing may involve sensitive data or credit consequences, so both require explicit review. The scanner cannot inspect an authenticated deal room or validate any specific vehicle record.
To pursue “Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment,” an effective outside agent should build an evidence packet before it proposes action. For Carvana, that packet should contain the original constraint, candidate facts and sources, timestamps or freshness markers, unresolved ambiguities, material terms, the identity of any third party receiving data, and the exact consequence of the next click. If a fact needed for “Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification” cannot be verified, the correct behavior is to mark it unknown or ask the user—not to synthesize a plausible value.
The safe stopping point also makes Carvana reruns comparable. A future audit can reuse the fixture “Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification” with the same target hostname, methodology version, and boundary, then ask whether evidence coverage increased and whether specific gaps became observable passes. Without that discipline, an apparent change could reflect a different target page, temporary bot response, personalization, scanner change, or broader task rather than an actual improvement to this commerce journey.
Strengths visible in this run
- web.robots-policy: robots.txt found — HTTP 200 AI agents are not explicitly blocked in robots.txt robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml
- web.llms-txt: llms.txt found — Quality: 3/3
- web.https: HTTP redirects to HTTPS
- web.security-headers: Content-Security-Policy present Frame embedding protection present X-Content-Type-Options nosniff present
- web.captcha: No obvious CAPTCHA detected
- web.secret-exposure: No obvious secrets detected in HTML
For Carvana, the recorded strengths reduce orientation cost for “Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment.” Public protocol truth helps an agent decide where it may crawl and which machine-readable surfaces exist; legal links and security signals establish part of the operating context; structured content can reduce brittle extraction. The first recorded strength in this run was “web.robots-policy: robots.txt found — HTTP 200 AI agents are not explicitly blocked in robots.txt robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml.” None of these observations authorizes action on behalf of a person. They are foundations for this journey, not substitutes for a task-level test.
Confirmed gaps and observation limits
- Observation limitation (not a target failure): Playwright DOM audit unavailable: Verify the Browserless token and WebSocket endpoint to enable deep DOM + accessibility checks.
- Observation limitation (not a target failure): Playwright/browser compatibility checks skipped: Verify the Browserless token and WebSocket endpoint to enable real browser automation checks.
- web.sitemap-discovery: robots.txt references sitemap — https://www.carvana.com/buy/sitemap.xml sitemap.xml missing or invalid — https://www.carvana.com/sitemap.xml
- web.agent-instructions: Missing agent instructions (agents.md / AGENTS.md) — Add one to site or repo
- web.agent-card: No agent manifest found — Checked /.well-known/agent-card.json and ai-agent.json
- web.legal-trust: Privacy policy not verified — HTTP 403 Terms of service not verified — HTTP 403
- commerce.readiness: No machine-readable product feed found — Checked link rel=alternate + common paths
- 19 checks were unobservable; this limits conclusions about rendered interaction, accessibility, navigation, and task completion.
For the Carvana task, the key discipline is not to convert missing evidence into either a target failure or a success. Browser availability, bot defenses, regional routing, consent layers, authentication, and dynamic rendering narrowed what could be concluded about “Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification.” This profile avoids percentile language and does not claim that Carvana is better or worse than another company. The useful question is whether the observed evidence supports the stated goal and what still needs verification at the declared boundary: Stop before reserving a vehicle, starting financing or a credit check, submitting a trade-in, uploading identification, scheduling delivery, signing, or paying.
The broader commerce pattern
Across commerce targets, the recurring pattern is that discovery can be public while consequence accumulates later. Catalog facts, inventory, price, delivery, recurring enrollment, identity, payment, and order submission are distinct states. A responsible agent should not compress them into one “buy” capability. The useful design unit is a previewable transaction with evidence freshness and separate confirmations for material changes. Applied to Carvana, the pattern is concrete: The task limits the agent to research and comparison.
Across the second-wave cohort, Carvana illustrates the separation between internal agent strategy and external public web readiness. Companies can sell, deploy, or publicly discuss sophisticated agents while a marketing site exposes only part of the evidence an unauthenticated outside agent needs. For this profile, the highest-leverage response is specific: Provide a stable machine-readable vehicle evidence packet with source, freshness, mileage, history, inspection, warranty, return, location, and delivery fields. That is a growth and trust opportunity because public evaluation increasingly happens before a buyer reaches a product, sales team, or authenticated workflow.
The third pattern is that coverage deserves primary visual weight. Applicability-aware evaluation avoids treating an absent optional surface or an unobservable check as a confirmed target failure. The tradeoff is that positive findings can rest on a small evidence denominator. Readers should interpret 37% coverage as a binding limit on every conclusion in this article.
Five corrections that would improve the journey
- Provide a stable machine-readable vehicle evidence packet with source, freshness, mileage, history, inspection, warranty, return, location, and delivery fields.
- Separate vehicle price, taxes, fees, shipping, trade-in, financing assumptions, and optional protection products before any monthly-payment presentation.
- Use explicit confirmation gates for reservation, credit authorization, trade-in submission, identity upload, contract signature, delivery, and payment.
- Make inventory-state changes and expiration visible so an agent cannot imply that a comparison remains current after the evidence window.
- Publish a safe reference journey using a non-reserving sandbox or archived vehicle fixture to demonstrate end-to-end agent review.
The Carvana recommendation order follows consequence, not novelty. The first move—provide a stable machine-readable vehicle evidence packet with source, freshness, mileage, history, inspection, warranty, return, location, and delivery fields—addresses the evidence needed for this fixed journey. Clear scope and confirmation matter more than adding another discovery file. A new agent endpoint would be valuable only when its identity, permissions, idempotency, audit, revocation, and human-override behavior fit the safe stopping point recorded above.
What this result does—and does not—say
For “Narrow a used-vehicle search without creating a reservation, financing application, or trade-in commitment.,” the diagnostic says only that AgentReady observed the listed public signals and observation limits on www.carvana.com at the recorded time. It does not say that Carvana approved the audit, that an employee reviewed it, that authenticated product behavior matches the homepage, or that a live transaction would succeed. In particular, it does not cross this boundary: Stop before reserving a vehicle, starting financing or a credit check, submitting a trade-in, uploading identification, scheduling delivery, signing, or paying. It also does not test every locale, device, account tier, subsidiary, app, API, connector, marketplace listing, or third-party handoff.
The scan uses heuristics for accessibility, structure, security, bot handling, legal trust, commerce, and agent conventions. Heuristics can produce false positives and false negatives. Policy pages are checked for existence and discoverability, not legal sufficiency. Security checks inspect public response signals, not vulnerabilities. Absence of obvious secrets is not proof that no secret exists. Browser and direct-fetch paths can receive different content. Results can change when the site, scanner, browser provider, or methodology changes.
The safe use of this Carvana article is as a reproducible starting point for “Find two used compact SUVs under a hypothetical total budget, compare vehicle history, mileage, delivery availability, warranty and return information, and estimate which facts still require verification.” Save the raw report, verify material observations against the live route and the cited source “Carvana announces record second quarter 2026 results,” request correction of factual errors, and rerun the same task after a fix. Do not use this diagnostic alone for procurement, investment, legal, security, accessibility, employment, housing, health, or purchasing decisions.
Methodology, sources, and correction route
The raw artifact is stored as `content/agentic-index/wave2/raw/carvana.json`. The current model emits 34 stable checks with pass, partial, fail, not-applicable, and unobservable states. Unobservable checks lower coverage rather than being treated as target failures. Optional surfaces activate only when positively observed. The fixed task and safe stopping point are editorial test fixtures for a later full journey run; the current evidence comes from the public diagnostic.
Official company sources used for strategic context:
- Carvana announces record second quarter 2026 results — Carvana Investor Relations; checked August 27, 2026.
- Carvana 2025 annual report — Carvana Investor Relations; checked August 27, 2026.
Carvana can request a factual correction through [the AgentReady index correction route](/contact?subject=index-correction). A correction should identify the exact statement, provide a first-party URL or reproducible evidence, and state whether the issue affects the timestamped result or only current behavior. Material corrections should preserve the original timestamp and methodology so readers can distinguish a historical result from a new scan.
Sources and observation record
- Carvana announces record second quarter 2026 results — Carvana Investor Relations; checked 2026-08-27T20:49:00.000Z
- Carvana 2025 annual report — Carvana Investor Relations; checked 2026-08-27T20:49:00.000Z
AgentReady is not affiliated with or endorsed by Carvana. Company and product names belong to their respective owners. This independent diagnostic can change when the site, observation coverage, browser availability, or methodology changes.
Found an error or materially changed behavior? Request a correction or removal.
Your site, the same evidence contract
See what an agent can observe and what to fix first.
Run a public diagnostic, save the report, and verify the fixes after deployment.