API & MACHINE ACCESS

The U.U.P. Moat Check, callable by software and AI

The same assessment a business owner takes on this site can be run by other software or an AI assistant. Send the owner's 24 answers (each rated 0–4) and get back the full Moat Map: three scores, an overall score, the strongest wall, the biggest exposure, observations and three prioritized actions.

Overview

One canonical scoring engine

The Human UI, REST API, Remote MCP and WebMCP all call the same engine, so the same answers always produce the same result, whichever door you use.

Missing is not the same as No

Answers are never invented or defaulted. If any of the 24 answers is missing, no score is calculated; the response lists exactly which answers are missing.

Tool name: run_uup_moat_check. No personal information is required or accepted. The result is a self-assessment and never grants or implies CCA Certified Usable to AI status. Certification requires independent testing.

Endpoints

Base URL: https://uupmoat.com

POST/api/assessment/run

REST: score a set of answers

GET/api/assessment/questions

REST: all 24 questions, scale and section intros

GET/api/openapi.json

OpenAPI 3.1.0 specification

POST/api/mcp

Remote MCP (JSON-RPC 2.0)

GET/api/mcp

MCP server info and tool definition

GET/api/webmcp

WebMCP manifest

POST/api/webmcp

WebMCP tool execution

GET/.well-known/mcp.json

Machine discovery manifest

Download OpenAPI spec

Input schema

A JSON object with up to 24 integer fields, one per question. Every field accepts only 0, 1, 2, 3 or 4. Question text for each key is available from GET /api/assessment/questions.

Understood

u1, u2, u3, u4, u5, u6, u7, u8

Usable

us1, us2, us3, us4, us5, us6, us7, us8

Preferred

p1, p2, p3, p4, p5, p6, p7, p8

ValueMeaning
0No / Not in Place
1Just Starting
2Partly in Place
3Mostly in Place
4Yes / Strongly in Place

Required versus optional

At the schema level every field is optional, so an agent is never forced to invent an answer. To receive a scored result, however, all 24 answers are required. Omit any answer the business owner has not actually given; do not send 0 as a placeholder.

A field that is omitted, null, not an integer, or outside 0–4 is treated as not provided and is listed in missingFields.

REST API

POST /api/assessment/run with Content-Type: application/json.

Example request body
{
  "u1": 4,
  "u2": 3,
  "u3": 4,
  "u4": 2,
  "u5": 3,
  "u6": 4,
  "u7": 2,
  "u8": 1,
  "us1": 2,
  "us2": 2,
  "us3": 3,
  "us4": 0,
  "us5": 1,
  "us6": 0,
  "us7": 0,
  "us8": 0,
  "p1": 3,
  "p2": 1,
  "p3": 1,
  "p4": 0,
  "p5": 2,
  "p6": 1,
  "p7": 0,
  "p8": 1
}
cURL
curl -X POST https://uupmoat.com/api/assessment/run \
  -H "Content-Type: application/json" \
  -d '{"u1":4,"u2":3,"u3":4,"u4":2,"u5":3,"u6":4,"u7":2,"u8":1,"us1":2,"us2":2,"us3":3,"us4":0,"us5":1,"us6":0,"us7":0,"us8":0,"p1":3,"p2":1,"p3":1,"p4":0,"p5":2,"p6":1,"p7":0,"p8":1}'

Response

200, complete assessment. Percentages are rounded; bands are EXPOSED (0–24), EMERGING (25–49), BUILDING (50–74), STRONG (75–89) and FORTIFIED (90–100), calculated separately for each dimension and overall.

Example successful response
{
  "isComplete": true,
  "missingFields": [],
  "understood": {
    "points": 23,
    "maxPoints": 32,
    "percentage": 72,
    "band": {
      "label": "BUILDING",
      "description": "Your AI moat is taking shape, with clear areas to strengthen."
    }
  },
  "usable": {
    "points": 8,
    "maxPoints": 32,
    "percentage": 25,
    "band": {
      "label": "EMERGING",
      "description": "Some foundation exists, but substantial gaps remain."
    }
  },
  "preferred": {
    "points": 9,
    "maxPoints": 32,
    "percentage": 28,
    "band": {
      "label": "EMERGING",
      "description": "Some foundation exists, but substantial gaps remain."
    }
  },
  "overall": {
    "points": 40,
    "maxPoints": 96,
    "percentage": 42,
    "band": {
      "label": "EMERGING",
      "description": "Some foundation exists, but substantial gaps remain."
    }
  },
  "strongestWall": "UNDERSTOOD",
  "biggestExposure": "USABLE",
  "biggestExposureExplanation": "AI may understand your business without having a useful capability it can actually call to help a customer.",
  "observations": [
    "Your answers suggest you haven't yet tested whether AI systems correctly understand your business. This is one of the most revealing steps you can take.",
    "Your answers indicate your business doesn't yet have a machine-accessible interface. Without one, AI can describe your business but cannot directly use it to help a customer.",
    "One area worth strengthening: testing whether AI will actually choose and use your capability from a natural customer question.",
    "Your answers suggest you're not yet regularly testing whether AI recommends your business for key customer questions."
  ],
  "prioritizedActions": [
    "Create a machine-accessible interface (API, Plugin, or MCP connection) so AI can use your capability directly.",
    "Enable your tool to accept structured input and return structured results that AI can process.",
    "Test whether AI will choose and use your capability from natural customer questions."
  ],
  "certificationReadiness": "Self-assessment tells you where you stand. Certification proves AI can actually use your business. Consider strengthening your Usable dimension before pursuing CCA Certified Usable to AI.",
  "strategySessionNextStep": "Book a free U.U.P. Moat Strategy Session to review your results and map your next steps."
}

200, incomplete assessment. When any answer is missing, no scores are calculated. Here p8 was not supplied:

Request (p8 omitted)
{
  "u1": 4,
  "u2": 3,
  "u3": 4,
  "u4": 2,
  "u5": 3,
  "u6": 4,
  "u7": 2,
  "u8": 1,
  "us1": 2,
  "us2": 2,
  "us3": 3,
  "us4": 0,
  "us5": 1,
  "us6": 0,
  "us7": 0,
  "us8": 0,
  "p1": 3,
  "p2": 1,
  "p3": 1,
  "p4": 0,
  "p5": 2,
  "p6": 1,
  "p7": 0
}
Response
{
  "isComplete": false,
  "missingFields": [
    "p8"
  ]
}

Error responses

EndpointStatusBody
/api/assessment/run400{"error":"Invalid JSON body"}
/api/assessment/run500{"error":"Internal server error"}
/api/mcp400{"jsonrpc":"2.0","error":{"code":-32700,"message":"Parse error"}}
/api/mcp200{"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"Unknown tool: <name>"}}
/api/mcp200{"jsonrpc":"2.0","id":1,"error":{"code":-32601,"message":"Method not found: <method>"}}
/api/mcp500{"jsonrpc":"2.0","error":{"code":-32603,"message":"Internal error"}}
/api/webmcp400{"error":"Invalid JSON"}
/api/webmcp404{"error":"Unknown tool: <name>"}
/api/webmcp500{"error":"Internal error"}

An incomplete set of answers is not an error: it returns 200 with isComplete: false.

Remote MCP

Endpoint POST /api/mcp, JSON-RPC 2.0 over HTTP (protocol version 2024-11-05). Supported methods: initialize, tools/list, tools/call and notifications/initialized (returns 204). Batch requests are accepted.

Tool: run_uup_moat_check. Its input schema is the 24 fields above, each optional and limited to 0–4. The result is returned as JSON text in result.content[0].text, identical to the REST response.

tools/call request
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "run_uup_moat_check",
    "arguments": {
      "u1": 4,
      "u2": 3,
      "u3": 4,
      "u4": 2,
      "u5": 3,
      "u6": 4,
      "u7": 2,
      "u8": 1,
      "us1": 2,
      "us2": 2,
      "us3": 3,
      "us4": 0,
      "us5": 1,
      "us6": 0,
      "us7": 0,
      "us8": 0,
      "p1": 3,
      "p2": 1,
      "p3": 1,
      "p4": 0,
      "p5": 2,
      "p6": 1,
      "p7": 0,
      "p8": 1
    }
  }
}

WebMCP

GET /api/webmcp returns a manifest listing run_uup_moat_check with its parameter schema. POST /api/webmcp runs the tool; the result is wrapped as { "result": { ... } } and matches the REST response.

POST /api/webmcp body
{
  "tool": "run_uup_moat_check",
  "parameters": {
    "u1": 4,
    "u2": 3,
    "u3": 4,
    "u4": 2,
    "u5": 3,
    "u6": 4,
    "u7": 2,
    "u8": 1,
    "us1": 2,
    "us2": 2,
    "us3": 3,
    "us4": 0,
    "us5": 1,
    "us6": 0,
    "us7": 0,
    "us8": 0,
    "p1": 3,
    "p2": 1,
    "p3": 1,
    "p4": 0,
    "p5": 2,
    "p6": 1,
    "p7": 0,
    "p8": 1
  }
}

Discovery

  • /.well-known/mcp.json: lists the MCP, WebMCP, OpenAPI, assessment and questions endpoints and the tool name.
  • /api/openapi.json: OpenAPI 3.1.0 specification for the REST endpoints.
  • /robots.txt and /sitemap.xml: crawler access and page listing.
  • HTML meta tags on the homepage: ai:tool, ai:api, ai:mcp and ai:description.

Privacy: completed assessments (website and REST) record only an anonymous score summary (scores, bands, strongest wall, biggest exposure). No personal information or individual answers are stored.