Backblazebackblaze.com
Backblaze's API program shows genuine strength in discoverability, contract quality, and documentation structure — partners and agents can find and parse the API surface without friction. The two areas that need immediate attention are change communication and onboarding speed: there is no published changelog anywhere in the spec or docs, meaning partners and their agents have no way to anticipate breaking changes, and zero code samples across 18 sampled documentation pages means a developer or coding agent must reverse-engineer every integration from scratch.
API DesignA clean, typed, well-governed API contract agents can reason about3 pass2 warn0 fail86A
| Signal | Points | Findings | Rationale | |
|---|---|---|---|---|
| pass | Schema coverage & depthvia sdk | 25/25 | 354/355 (100%) public params are fully typed (no any/**kwargs). Analyzer reports not all methods have a derivable input schema. Investigated: sdk 100%, spec 42%. | Typed, complete request/response schemas are what make agent function-calling possible. |
| warn | Machine-readable, versioned contractvia spec | 21.9/25 | The API sets a version ("1.0.0") but exposes no versioning scheme in the URL, a header, or the media type, so an agent can't pin to a specific version. Investigated: spec 88%, docs 75%. Fix: Pick a versioning scheme (URL path /v1/, Accept: application/vnd.x+json, or a version header) and apply it consistently. | A current OpenAPI version with a declared versioning scheme lets agents reason about the contract. |
| pass | Security & governance hygienevia spec | 15/15 | No credential-shaped strings detected in spec. Investigated: spec 100%, sdk 100%, wellknown 0%. | No leaked secrets, no critical lint violations, no OWASP API Top-10 spec smells, and a published vulnerability-disclosure channel. |
| warn | Auth declared & discoverablevia spec | 12.5/25 | The spec declares no authentication scheme, so an agent can't tell how to authenticate a request. Investigated: spec 50%, docs 50%. Fix: Declare an authentication scheme and apply it globally or on every operation that requires credentials. | Agents can only call an API when they can determine its auth posture — a declared scheme, or an explicit statement that none is required. |
| pass | Example coveragevia spec | 10/10 | 100% of parameters and responses (23 of 23) include example values, grounding an agent in real payload shapes. Investigated: spec 100%, sdk 100%, docs 0%. | Examples carry shape semantics schemas under-specify — for humans and agents alike. |
Developer ExperienceThe context both developers and agents need to integrate fast — onboarding, code samples, complete descriptions and worked examples2 pass1 warn2 fail65C
| Signal | Points | Findings | Rationale | |
|---|---|---|---|---|
| pass | Self-service developer portalvia docs | 29/29 | Self-service signup available at https://www.backblaze.com/sign-up/cloud-backup, with a free tier or sandbox documented — an agent can onboard without contacting sales. Investigated: docs 100%. | A first call without a human in the loop — self-serve credentials, a free tier, or an API that needs none. |
| pass | Description completenessvia spec | 15/15 | Only 63% of operations and parameters have substantive descriptions (29 of 35 ops, 10 of 23 params; target 90%+). Investigated: spec 100%, sdk 100%. | Complete descriptions are the context humans and agents need to use endpoints. |
| warn | Quickstart presentvia docs | 12.5/25 | Quickstart page is reachable at https://www.backblaze.com/get-started (1 variants scanned) but has no runnable code sample in its HTML or .md variant, so there's nothing to copy and run. Investigated: docs 50%. Fix: Add a copy-pasteable curl or SDK call, with the expected response, to the quickstart page (or its .md variant). | A quickstart is the fastest path from landing page to first successful call. |
| fail | Code samples in docsvia docs | 0/18 | No code samples detected across 18 sampled docs pages, so a coding agent gets no ready-to-use examples. Investigated: docs 0%. Fix: Add copy-pasteable code samples to API reference and quickstart pages. | Multi-language samples shorten time-to-first-call. |
| fail | Changelog publishedvia spec | 0/13 | No changelog link or mention appears in the spec, so an agent can't tell what changed before something breaks. Investigated: spec 0%, docs 0%. Fix: Publish a structured changelog (e.g., /changelog.json or releases.atom) and reference it in info or externalDocs. | A published changelog lets partners track changes without surprise. |
Agent DiscoveryPartners and their agents can find your APIs — llms.txt, registries, crawlable and reachable docs2 pass2 warn0 fail91A+
| Signal | Points | Findings | Rationale | |
|---|---|---|---|---|
| pass | llms.txt present, valid & comprehensivevia sdk | 30/30 | llms.txt is present at llms.txt. Investigated: sdk 100%, docs 50%. | A valid, comprehensive llms.txt is the machine-readable entry point for agents. |
| pass | Registry & SDK presencevia docs | 28/28 | Indexed on Context7 (websites/backblaze_apidocs, 962 snippets). Investigated: docs 100%, sdk 100%, cli 0%. | Listing in MCP registries and publishing SDKs puts the API where agents and their tooling look. |
| warn | Docs reachable, not hard auth-gatedvia docs | 22.5/30 | Server ignores Accept: text/markdown header (0/50 sampled pages return markdown); 49 rate-limited (HTTP 429). Investigated: docs 75%. | Agents can only index and fetch docs they can reach — past auth gates and over correct HTTP semantics. |
| warn | Crawlable / AEOvia wellknown | 9/12 | Sitemap has lastmod on only 100% of entries, or its newest entry is over 90 days old. Investigated: wellknown 75%. Fix: Add accurate <lastmod> values to sitemap entries — AI-powered search uses them to prioritize crawling. | Bots allowed plus a fresh sitemap make docs findable by agent crawlers. |
Agent UnderstandingAgents can correctly interpret your APIs — machine-readable errors, consistent descriptions, structured data, parseable docs3 pass3 warn0 fail88A
| Signal | Points | Findings | Rationale | |
|---|---|---|---|---|
| pass | Machine-readable errors (RFC 9457)via sdk | 28/28 | Single base error "B2Error" with 99 subclasses. Investigated: sdk 100%, spec 0%, docs 0%. | RFC 9457 problem details and a documented error-code inventory let agents parse failures without burning tokens. |
| pass | Operation purpose clarityvia spec | 25/25 | 100% of operations (35 of 35) have both a clear summary and a descriptive name, so an agent can pick the right endpoint. Investigated: spec 100%, sdk 100%. | Agents select the right endpoint from its summary + operationId; clear, named operations make tool-selection reliable — the strongest driver of correct tool choice. |
| warn | Agent-navigable, token-efficient docsvia docs | 16.6/22 | No sampled pages support .md URLs (0/50 tested). Investigated: docs 75%. | Server-rendered, clean, small-footprint docs are what an agent can cheaply fetch and parse correctly. |
| pass | Agent instructions file (AGENTS.md)via sdk | 10/10 | Agent context file present: agents.md (AGENTS.md). Investigated: sdk 100%, wellknown 0%. | An AGENTS.md gives coding agents explicit setup, auth, and usage instructions to interpret and operate the API — beyond llms.txt's link index. |
| warn | Docs structured datavia docs | 4/8 | Only OpenGraph/meta tags across 2 assessed pages — no JSON-LD for AI answer engines to cite. Investigated: docs 50%. Fix: Emit JSON-LD with Article/TechArticle @type and dateModified in the rendered docs head. | Structured data (JSON-LD/schema.org) on docs pages gives agents an unambiguous parse target and is what answer engines cite. Detected on the JS-rendered head (Firecrawl) for a bounded page budget, so JS-injected JSON-LD is now caught; pages we can't render are excluded rather than failed. |
| warn | Description consistency across surfaces | 2.2/7 | Mean pairwise description similarity across 3 surfaces (spec, docs, sdk) is 11% (threshold 35% for full credit). Fix: Align the API description across spec, docs, and SDK so an agent reading any one surface gets the same story. | Every surface tells the same story about what the product is. |
Agent UsabilityAgents have the context to use your APIs reliably, not just find them3 pass0 warn1 fail76B
| Signal | Points | Findings | Rationale | |
|---|---|---|---|---|
| pass | Idempotency documentedvia sdk | 27/27 | Built-in retry machinery is present (grep-derived). Investigated: sdk 100%, spec 0%, docs 0%. | Documented idempotency lets agents retry safely. |
| pass | Sandbox separationvia sdk | 20/20 | Sandbox environments are exposed (sandbox). Investigated: sdk 100%, spec 0%, docs 0%. | An isolated environment lets agents exercise destructive operations safely. |
| pass | Runnable collection with test scriptsvia sdk | 9/9 | README is present and includes a runnable quickstart. Investigated: sdk 100%, platform 50%. | A public, maintained collection with assertions is runnable truth agents validate against. |
| fail | Rate-limit signalingvia spec | 0/22 | No rate-limit response headers are documented, so an agent can't tell when it is approaching a limit and will get throttled. Investigated: spec 0%, docs 0%. Fix: Add x-ratelimit-* response headers and document retry-after semantics. | Machine-readable rate-limit headers let agents throttle adaptively. |
| na | Pagination documented & consistent | —/22 | No surface produced evidence for this capability in this run. | Consistent, documented pagination lets agents traverse collections. |
Resources Discovered
The public resources we found for Backblaze — the evidence behind the score. All discovered from public sources; nothing here requires access to your systems.
| Agent hints | Context7 (962) |
|---|---|
| APIs analyzed | 2 — Backblaze B2 Cloud Storage Native API, Backblaze B2 Cloud Storage S3-Compatible API |