# Bank of America — API Agent Score

> Score: 63/100 (Grade: C) | Domain: bankofamerica.com | Rubric: 1.0.0 | Checked: July 24, 2026

Bank of America scored 63/100 (C), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/bankofamerica)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 63/100 (C)
- Classification: partially-ready

## Category Scores

- API Design: 56/100 (D)
- Developer Experience: 75/100 (B)
- Agent Discovery: 69/100 (C)
- Agent Understanding: 78/100 (B)
- Agent Usability: 45/100 (F)

## Check Results

### API Design

- [pass] Machine-readable, versioned contract — Versioning declared (info.version="0.0.1") and header-versioning detected. Investigated: spec 100%, docs 100%.
- [warn] Schema coverage & depth — 86% of operations have documented schemas (target 95%+). Investigated: spec 67%.
- [fail] Auth declared & discoverable — No securitySchemes declared. Investigated: spec 0%, docs 0%.
- [fail] Security & governance hygiene — 4 credential-shaped strings detected in spec: bearer-jwt (×4). Investigated: spec 0%, wellknown 0%.
- [fail] Example coverage — 34% example coverage. Investigated: spec 0%, docs 0%.

### Developer Experience

- [pass] Self-service developer portal — Self-service signup at https://www.bankofamerica.com/deposits/student/before-you-apply/?cm_mmc=DEP-Checking-_-Module%20Ad-_-DC16LT00AF_SMS_START-_-StudentCheckingSignage; no free tier or sandbox language detected. Investigated: docs 100%.
- [pass] Description completeness — 88% description completeness (target 90%+). Investigated: spec 100%.
- [pass] Changelog published — Newest official SDK activity 2 day(s) ago. Investigated: sdk 100%, spec 0%, docs 0%.
- [warn] Quickstart present — Quickstart page reachable (12 variants scanned starting at https://developer.bankofamerica.com/CPODevPortal/apidocs/public/default.page?resumePath=https%3A%2F%2Ffedsso-gb.bankofamerica.com%2Fas%2FBnCh468pxG%2Fresume%2Fas%2Fauthorization.ping&vnd_pi_requested_resource=https%3A%2F%2Fdeveloper.bankofamerica.com%2Fquickstart&vnd_pi_application_name=A11697DevPortal&client_id=A11697DevPortal) but no runnable code sample detected in HTML or .md variant. Investigated: docs 50%.
- [fail] Code samples in docs — No detectable code samples across 3 sampled docs pages. Investigated: docs 0%.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (websites/developer_bankofamerica_cashpro-developer-studio, 14 snippets). Investigated: docs 100%, sdk 100%, cli 0%.
- [warn] Docs reachable, not hard auth-gated — 1 of 1 pages return 200 for non-existent URLs (soft 404). Investigated: docs 50%.
- [warn] llms.txt present, valid & comprehensive — No llms.txt found at any candidate location (https://developer.bankofamerica.com/llms.txt, https://developer.bankofamerica.com/docs/llms.txt). Investigated: docs 33%.
- [warn] Crawlable / AEO — Sitemap present (0 entries) but carries no lastmod values. Investigated: wellknown 75%.

### Agent Understanding

- [pass] Machine-readable errors (RFC 9457) — 13 distinct 4xx/5xx response codes documented. Investigated: docs 100%, spec 50%.
- [pass] Operation purpose clarity — 98% of operations have a clear summary + operationId an agent can select on. Investigated: spec 100%.
- [warn] Agent-navigable, token-efficient docs — No pages support .md URLs (0/1 tested). Investigated: docs 71%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [fail] Docs structured data — Neither JSON-LD nor OpenGraph/meta tags detected across 3 sampled pages — likely a CSR-only docs site. Investigated: docs 0%.
- [skip] Description consistency across surfaces — Only 1 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [pass] Sandbox separation — Sandbox server declared but no distinguishable test credentials in scheme descriptions. Investigated: spec 100%, docs 100%.
- [fail] Idempotency documented — 5% of mutating operations document idempotency. Investigated: spec 0%, docs 0%.
- [fail] Rate-limit signaling — No rate-limit response headers documented. Investigated: spec 0%, docs 0%.
- [fail] Pagination documented & consistent — 1 list endpoint(s) exist but no pagination params found. Investigated: spec 0%, docs 0%.
- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.

## Executive Summary

Bank of America's API program shows relative strength in agent discoverability and documentation reachability, but faces critical gaps in two areas that directly threaten partner integration success: agent usability and API design. Partners and their AI agents currently cannot rely on the API for production-grade workflows — there is no runnable reference, no idempotency or rate-limit guidance, and no pagination contract — while the API contract itself lacks declared auth, security hygiene, and example coverage. Prioritizing operational reliability and a trustworthy, executable contract will unlock self-serve partner onboarding and give AI agents the grounded context they need to integrate correctly.
