# Block — API Agent Score

> Score: 56/100 (Grade: D) | Domain: block.xyz | Rubric: 1.0.0 | Checked: July 30, 2026

Block scored 56/100 (D), classified "not-ai-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/block)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 56/100 (D)
- Classification: not-ai-ready

## Category Scores

- API Design: 55/100 (D)
- Developer Experience: 87/100 (A)
- Agent Discovery: 76/100 (B)
- Agent Understanding: 49/100 (F)
- Agent Usability: 40/100 (F)

## Check Results

### API Design

- [pass] Example coverage — Code samples present on 2/3 pages across 2 language(s); broader multi-language coverage missing. Investigated: docs 100%.
- [fail] Security & governance hygiene — No security.txt at /.well-known/security.txt or /security.txt. Investigated: wellknown 0%.
- [skip] Machine-readable, versioned contract — No surface produced evidence for this capability in this run.
- [skip] Schema coverage & depth — No surface produced evidence for this capability in this run.
- [skip] Auth declared & discoverable — No surface produced evidence for this capability in this run.

### Developer Experience

- [pass] Self-service developer portal — Self-service signup at https://developer.squareup.com/docs/square-get-started; free tier / sandbox documented. Investigated: docs 100%.
- [pass] Code samples in docs — Code samples present on 2/3 pages across 2 language(s); broader multi-language coverage missing. Investigated: docs 100%.
- [pass] Changelog published — Newest official SDK activity 15 day(s) ago. Investigated: sdk 100%.
- [warn] Quickstart present — Quickstart page reachable (2 variants scanned starting at https://developer.squareup.com/docs/square-get-started) but no runnable code sample detected in HTML or .md variant. Investigated: docs 50%.
- [skip] Description completeness — No surface produced evidence for this capability in this run.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (websites/slack_dev_block-kit, 61 snippets). Investigated: docs 100%, sdk 100%, cli 0%, mcp 0%, wellknown 0%.
- [warn] Docs reachable, not hard auth-gated — Server ignores Accept: text/markdown header (0/50 sampled pages return markdown); 36 rate-limited (HTTP 429). Investigated: docs 75%.
- [warn] llms.txt present, valid & comprehensive — No llms.txt directive found in HTML of any of 23 sampled pages; 27 failed to fetch. Investigated: docs 38%.
- [warn] Crawlable / AEO — Sitemap present (5 entries) but carries no lastmod values. Investigated: wellknown 75%.

### Agent Understanding

- [warn] Agent-navigable, token-efficient docs — 1 of 50 sampled pages appear to be client-side rendered SPA shells (__next detected); agents using HTTP fetches will see no content; 3 more have page structure but little substantive content. Investigated: docs 50%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [fail] Docs structured data — Neither JSON-LD nor OpenGraph/meta tags detected across 2 assessed pages (2 JS-rendered). Investigated: docs 0%.
- [skip] Machine-readable errors (RFC 9457) — No surface produced evidence for this capability in this run.
- [skip] Operation purpose clarity — No surface produced evidence for this capability in this run.
- [skip] Description consistency across surfaces — Only 1 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.
- [skip] Idempotency documented — No surface produced evidence for this capability in this run.
- [skip] Rate-limit signaling — No surface produced evidence for this capability in this run.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.
- [skip] Sandbox separation — No surface produced evidence for this capability in this run.

## Executive Summary

Block's developer experience and onboarding foundation is a genuine strength — partners can get started without friction. However, the program has critical gaps in three areas that will block AI-agent adoption and erode partner trust: security governance hygiene in the API contract leaves partners exposed to compliance risk; there are no agent-readable instruction files or structured metadata for AI agents to discover and correctly interpret your APIs; and without runnable collections with test scripts, neither partners nor their agents have a verifiable, executable source of truth to build against. Prioritizing these three gaps will transform Block's API program from human-readable to agent-ready.
