ax-check.com
by Gauge
W
WSO2
wso2.com
ax-check.com
Checked 8 October 2026
D
38/100
Agents need your login
Pricing is clear, but docs and onboarding leave agents guessing
Pricing pages list plain tiers and limits (Growth from $119/mo, Enterprise custom), but the docs index is a stale blog list with no quickstart or install steps found.
5 fixes to start with
Concrete changes, backed by what we found.
Tell agents where to start and organize the links in /llms.txt.
llms.txt offers no navigation guidance or starting points; it is an undifferentiated list of articles.
List every offered API, MCP, and skills surface in /llms.txt.
llms.txt never mentions the offered API, MCP, or skills surfaces despite MCP blog content existing.
Recorded coding sessions
Same task, 3 models, no wso2.com account. Recorded 8 October 2026 on Pi.
3 recorded · 43s
43s · recorded
Session findings
Select a finding to see it in context.
›Thinking…
The user is asking about WSO2 — building a simple example, pricing, and manageability. Let me check the environment and see what's available.
Let me check the sandbox and see if there are WSO2-related things.
ls -la /sandbox/repo 2>/dev/null; echo "---"; env | grep -i -E "wso2|api_key|token" | sed 's/=.*/=<set>/'; echo "---"; ls ~/.config 2>/dev/null
Failedtotal 16
total 16 drwxr-xr-x 3 root root 4096 Sep 18 08:00 . drwxr-xr-x 7 root root 4096 Oct 8 08:13 .. drwxr-xr-x 8 root root 4096 Sep 24 20:05 .git -rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore --- PI_GATEWAY_API_KEY=<set> --- Command exited with code 2
Recorded tool call
{
"type": "tool_call",
"seq": 3,
"ts": "2026-10-08T08:13:37.983Z",
"name": "bash",
"turn": 1,
"input": {
"command": "ls -la /sandbox/repo 2>/dev/null; echo \"---\"; env | grep -i -E \"wso2|api_key|token\" | sed 's/=.*/=<set>/'; echo \"---\"; ls ~/.config 2>/dev/null"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-b84211bf2284b25d",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 6,
"ts": "2026-10-08T08:13:37.983Z",
"turn": 1,
"output": {
"content": [
{
"text": "total 16\ndrwxr-xr-x 3 root root 4096 Sep 18 08:00 .\ndrwxr-xr-x 7 root root 4096 Oct 8 08:13 ..\ndrwxr-xr-x 8 root root 4096 Sep 24 20:05 .git\n-rw-r--r-- 1 root root 408 Sep 18 08:00 .gitignore\n---\nPI_GATEWAY_API_KEY=<set>\n---\n\n\nCommand exited with code 2",
"type": "text"
}
],
"details": {}
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-b84211bf2284b25d",
"is_error": true,
"tool_kind": "shell"
}which curl python3 node; echo "---"; cat /etc/os-release | head -3
/usr/bin/curl
/usr/bin/curl /usr/local/bin/python3 /usr/local/bin/node --- PRETTY_NAME="Ubuntu 24.04.4 LTS" NAME="Ubuntu" VERSION_ID="24.04"
Recorded tool call
{
"type": "tool_call",
"seq": 4,
"ts": "2026-10-08T08:13:37.983Z",
"name": "bash",
"turn": 1,
"input": {
"command": "which curl python3 node; echo \"---\"; cat /etc/os-release | head -3"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-a001fbdc00186213",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 5,
"ts": "2026-10-08T08:13:37.983Z",
"turn": 1,
"output": {
"content": [
{
"text": "/usr/bin/curl\n/usr/local/bin/python3\n/usr/local/bin/node\n---\nPRETTY_NAME=\"Ubuntu 24.04.4 LTS\"\nNAME=\"Ubuntu\"\nVERSION_ID=\"24.04\"\n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-a001fbdc00186213",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
The repo is empty. There's no WSO2 credentials. Let me think about what WSO2 is: WSO2 is an open-source API management / integration company. Products: WSO2 API Manager (self-hosted, requires running a Java service stack locally), WSO2 Identity Server, and Choreo (their cloud/hosted SaaS platform).
The user wants: hosted product through SDK or API. WSO2's hosted offering is Choreo (choreo.dev), now rebranded... Choreo has a free tier. But it requires an account signup with credentials — no credentials present in env.
Let me check network access to see if anything is reachable.
Actually, the key honest answer: WSO2 API Manager is a self-hosted Java stack (Docker/K8s) — that's a local service stack, which is explicitly disallowed. Choreo is the hosted SaaS but requires account signup (OAuth via Google/GitHub/email) and there are no credentials in this sandbox. Let me verify network connectivity quickly to confirm.
Let me check.
cd /tmp && for u in https://choreo.dev https://apis.choreo.dev https://api.asgardeo.io https://wso2.com https://pypi.org; do printf "%s -> " "$u"; curl -s -o /dev/null -m 8 -w "%{http_code}\n" "$u" || echo "FAIL"; donehttps://choreo.dev -> 301
https://choreo.dev -> 301 https://apis.choreo.dev -> 404 https://api.asgardeo.io -> 302 https://wso2.com -> 403 https://pypi.org -> 200
Recorded tool call
{
"type": "tool_call",
"seq": 9,
"ts": "2026-10-08T08:13:41.902Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && for u in https://choreo.dev https://apis.choreo.dev https://api.asgardeo.io https://wso2.com https://pypi.org; do printf \"%s -> \" \"$u\"; curl -s -o /dev/null -m 8 -w \"%{http_code}\\n\" \"$u\" || echo \"FAIL\"; done"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-b31c856de0e58bf0",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 12,
"ts": "2026-10-08T08:13:43.343Z",
"turn": 1,
"output": {
"content": [
{
"text": "https://choreo.dev -> 301\nhttps://apis.choreo.dev -> 404\nhttps://api.asgardeo.io -> 302\nhttps://wso2.com -> 403\nhttps://pypi.org -> 200\n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-b31c856de0e58bf0",
"is_error": false,
"tool_kind": "shell"
}git -C /sandbox/repo log --oneline -5 2>/dev/null; git -C /sandbox/repo status --short | head
9ebf5fb Initial workspace
9ebf5fb Initial workspace
Recorded tool call
{
"type": "tool_call",
"seq": 10,
"ts": "2026-10-08T08:13:41.902Z",
"name": "bash",
"turn": 1,
"input": {
"command": "git -C /sandbox/repo log --oneline -5 2>/dev/null; git -C /sandbox/repo status --short | head"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-85e94ca8b44b7063",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 11,
"ts": "2026-10-08T08:13:41.902Z",
"turn": 1,
"output": {
"content": [
{
"text": "9ebf5fb Initial workspace\n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-85e94ca8b44b7063",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Network is up. But no credentials. Choreo requires an account (org, OAuth login) to create components/publish APIs. There's no WSO2/Choreo API key in the environment.
Let me quickly verify: is there any public/unauthenticated WSO2 API I can act on? Choreo's public APIs require tokens. Asgardeo (WSO2's hosted IAM) requires an org + client credentials to get a token.
So the honest answer: WSO2's hosted product (Choreo/Asgardeo) has an API-driven workflow, but it's gated behind account signup + OAuth client credentials, which aren't available here. And the classic product (API Manager) is a local Java/Docker service stack — explicitly disallowed.
Let me double-check whether there's anything usable without credentials — maybe check Choreo docs for a "public" endpoint, and confirm pricing. Let me do a quick check of pricing info and whether signup is self-serve.
Let me fetch Choreo pricing page.
cd /tmp && curl -sL -m 15 -A "Mozilla/5.0" "https://choreo.dev/pricing/" -o p.html -w "%{http_code}\n"; python3 - <<'EOF'
import re,html
t=open('/tmp/p.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'(?s)<(script|style|svg).*?</\1>','',t)
t=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\s+',' ',t)
i=t.lower().find('pricing'); print(t[max(0,i-200):i+3000])
EOF200
200 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. -->
Recorded tool call
{
"type": "tool_call",
"seq": 15,
"ts": "2026-10-08T08:13:48.432Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && curl -sL -m 15 -A \"Mozilla/5.0\" \"https://choreo.dev/pricing/\" -o p.html -w \"%{http_code}\\n\"; python3 - <<'EOF'\nimport re,html\nt=open('/tmp/p.html',encoding='utf-8',errors='ignore').read()\nt=re.sub(r'(?s)<(script|style|svg).*?</\\1>','',t)\nt=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\\s+',' ',t)\ni=t.lower().find('pricing'); print(t[max(0,i-200):i+3000])\nEOF"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-8e9a45ce53d2b830",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 20,
"ts": "2026-10-08T08:13:48.891Z",
"turn": 1,
"output": {
"content": [
{
"text": "200\n .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> \n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-8e9a45ce53d2b830",
"is_error": false,
"tool_kind": "shell"
}cd /tmp && curl -s -m 10 -o /dev/null -w "choreo-api-probe:%{http_code}\n" "https://apis.choreo.dev/service-registry/v0/" ; curl -s -m 10 "https://api.asgardeo.io/t/nonexistentorg/oauth2/token" -d "grant_type=client_credentials" -o /dev/null -w "asgardeo-probe:%{http_code}\n"choreo-api-probe:404
choreo-api-probe:404 asgardeo-probe:404
Recorded tool call
{
"type": "tool_call",
"seq": 17,
"ts": "2026-10-08T08:13:48.432Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && curl -s -m 10 -o /dev/null -w \"choreo-api-probe:%{http_code}\\n\" \"https://apis.choreo.dev/service-registry/v0/\" ; curl -s -m 10 \"https://api.asgardeo.io/t/nonexistentorg/oauth2/token\" -d \"grant_type=client_credentials\" -o /dev/null -w \"asgardeo-probe:%{http_code}\\n\""
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-9db27507be95bb93",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 21,
"ts": "2026-10-08T08:13:49.436Z",
"turn": 1,
"output": {
"content": [
{
"text": "choreo-api-probe:404\nasgardeo-probe:404\n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-9db27507be95bb93",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
Confirmed: pricing page is a JS app (can't scrape easily). Both hosted API probes return 404 without auth/org — no unauthenticated developer workflow available.
Let me try one more: check if Choreo docs state pricing/free tier, maybe via a docs site that's static.
Actually, I have enough. But let me try to get pricing facts from a static docs source to be accurate rather than guessing. Let me try choreo.dev/docs or the WSO2 pricing page with a different approach.
cd /tmp && for u in "https://choreo.dev/docs/" "https://wso2.com/pricing/" "https://wso2.com/api-management/pricing/"; do printf "%s -> " "$u"; curl -sL -m 12 -A "Mozilla/5.0" -o o.html -w "%{http_code} " "$u"; python3 -c "
import re,html,sys
t=open('/tmp/o.html',encoding='utf-8',errors='ignore').read()
t=re.sub(r'(?s)<(script|style|svg).*?</\1>','',t); t=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\s+',' ',t)
print(t[:400])
"; donehttps://choreo.dev/docs/ -> 200 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the developm
https://choreo.dev/docs/ -> 200 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> https://wso2.com/pricing/ -> 403 Just a moment... Enable JavaScript and cookies to continue https://wso2.com/api-management/pricing/ -> 403 Just a moment... Enable JavaScript and cookies to continue
Recorded tool call
{
"type": "tool_call",
"seq": 24,
"ts": "2026-10-08T08:13:52.146Z",
"name": "bash",
"turn": 1,
"input": {
"command": "cd /tmp && for u in \"https://choreo.dev/docs/\" \"https://wso2.com/pricing/\" \"https://wso2.com/api-management/pricing/\"; do printf \"%s -> \" \"$u\"; curl -sL -m 12 -A \"Mozilla/5.0\" -o o.html -w \"%{http_code} \" \"$u\"; python3 -c \"\nimport re,html,sys\nt=open('/tmp/o.html',encoding='utf-8',errors='ignore').read()\nt=re.sub(r'(?s)<(script|style|svg).*?</\\1>','',t); t=re.sub(r'<[^>]+>',' ',t); t=html.unescape(t); t=re.sub(r'\\s+',' ',t)\nprint(t[:400])\n\"; done"
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-8dbb1ee3cbf134de",
"tool_kind": "shell"
}Recorded tool result
{
"type": "tool_result",
"seq": 25,
"ts": "2026-10-08T08:13:55.144Z",
"turn": 1,
"output": {
"content": [
{
"text": "https://choreo.dev/docs/ -> 200 .js to refresh thee cache --> WSO2 Developer Platform You need to enable JavaScript to run this app. tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> \nhttps://wso2.com/pricing/ -> 403 Just a moment... Enable JavaScript and cookies to continue \nhttps://wso2.com/api-management/pricing/ -> 403 Just a moment... Enable JavaScript and cookies to continue \n",
"type": "text"
}
]
},
"run_id": "cmuz9ex49007g0iu1zrd2fury",
"tool_id": "chatcmpl-tool-8dbb1ee3cbf134de",
"is_error": false,
"tool_kind": "shell"
}›Thinking…
All pricing pages are JS-rendered or Cloudflare-blocked. I can't verify pricing numbers from here. I should be honest: I couldn't fetch verified pricing; give what's generally known and flag it as unverified.
Now, the verdict. The user said: "If this product has no developer workflow you can act on, say so plainly and stop."
WSO2 has two shapes:
- WSO2 API Manager / Identity Server — open source, but the workflow is: download, run a Java/Docker/K8s service stack locally. That's explicitly excluded by the user's constraints.
- Choreo (WSO2 Developer Platform) + Asgardeo — hosted SaaS with a REST API and CLI. But every action requires a self-serve account signup (interactive browser OAuth), an org, and OAuth client credentials. None exist in this sandbox, and I cannot complete an interactive signup.
So: there IS a hosted API-driven workflow in principle (Choreo), but it's blocked on credentials I can't self-provision. Per instructions, I should say so plainly and stop, not build fake scaffolding.
Should I write any files? The instruction says stop. I'll not scaffold. Maybe write a short findings note? That's arguably useful but the user said "stop". I'll keep it minimal — no files, just the answer. Actually a tiny note file could help, but "say so plainly and stop" — I'll respect that and not clutter the repo.
Let me be honest about what I verified vs. not:
- Verified: network reachable, repo empty, no WSO2/Choreo creds in env, Choreo/Asgardeo API endpoints 404 unauthenticated, pricing pages JS-gated/Cloudflare-blocked.
- Not verified: exact current pricing numbers.
Let me give the pricing picture as generally known, clearly labeled unverified.
Keep it concise.
I checked before writing any code. Short version: I'm blocked, and I'm stopping as instructed.
What I verified in this sandbox
| Check | Result |
|---|---|
| Repo state | /sandbox/repo — empty except .git + .gitignore |
| Credentials | No WSO2/Choreo/Asgardeo key or token in env (only an unrelated PI_GATEWAY_API_KEY) |
| Network | Up (pypi.org 200) |
apis.choreo.dev unauthenticated | 404 |
api.asgardeo.io/t/<org>/oauth2/token unauthenticated | 404 |
Pricing pages (choreo.dev/pricing, wso2.com/pricing) | JS-only SPA / Cloudflare 403 — not readable from here |
Why there's no workflow I can act on
WSO2 ships in two shapes, and neither is actionable here:
-
WSO2 API Manager / Identity Server (the classic product, open source). The only real workflow is download-and-run: a Java service, or the Docker/K8s compose stack, then talk to its Publisher/Store REST APIs. That is exactly the "local service stack / long-running command" you told me not to start.
-
Choreo (WSO2 Developer Platform) and Asgardeo — the hosted SaaS, which does have a REST API and CLI. But every call needs an organization plus OAuth2 client credentials obtained through an interactive browser signup (Google/GitHub/email). I can't complete that, and no credentials were provided. There is no unauthenticated or sandbox tier I found — both API probes 404'd.
So: WSO2 does have an API-driven developer workflow in principle, but it's gated behind an account I cannot self-provision. Building scaffolding against it would mean inventing credentials and shipping untested code, so I stopped instead of doing that.
Pricing (⚠️ unverified — I could not fetch it)
Both pricing pages are JavaScript-rendered or bot-blocked, so I could not confirm any current number. What's generally understood, treat as needing your own confirmation:
- WSO2 API Manager / Identity Server (self-hosted): the software itself is Apache-2.0 free. You pay for infrastructure, plus optionally WSO2 commercial support subscriptions, sold per product/environment on an annual basis.
- Choreo (hosted): freemium. A free tier with limited component/API counts and throughput, then paid plans scaling by usage and number of developers/components, with enterprise tiers for private data planes and SSO/support.
- Asgardeo (hosted IAM): freemium on monthly active users, with paid tiers above the free MAU allowance.
Get exact figures from wso2.com/pricing and choreo.dev/pricing in a real browser.
Will this be easy for me to manage?
Honestly: no, not in this environment.
- Self-hosted API Manager is a stateful JVM service with a config-heavy XML/TOML surface, a database backend, and several coupled components (gateway, key manager, traffic manager). That's a lot of long-lived state for an agent to operate reliably, and it's off-limits per your constraints anyway.
- Choreo would be good for me once unblocked — declarative, REST/CLI driven, no state to babysit. But it's credential-gated, and its docs and console are JS-rendered SPAs, which I can't read from a shell. That's a real friction point even after auth.
To unblock me
Give me one of these and I'll build the example immediately:
- A Choreo org + client ID/secret (or a
CHOREO_PAT), or - An Asgardeo org name + client ID/secret, or
- A WSO2 API Manager instance you've already deployed elsewhere, with its base URL + an OAuth token.
With any of those I'd write a small runnable script — e.g. publish a simple REST API and invoke it through the gateway, or mint an Asgardeo token and call a protected endpoint — as a single file plus a README.
AX Fundamentals
23 checks. Open an area for details.
This check is a quick preview. Test more tasks and models with Gauge Agents.
Test your product with Gauge Agents