# Citi — API Agent Score

> Score: 60/100 (Grade: C) | Domain: citi.com | Rubric: 1.0.0 | Checked: July 24, 2026

Citi scored 60/100 (C), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/citi)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 60/100 (C)
- Classification: partially-ready

## Category Scores

- API Design: 81/100 (A)
- Developer Experience: 58/100 (D)
- Agent Discovery: 65/100 (C)
- Agent Understanding: 68/100 (C)
- Agent Usability: 41/100 (F)

## Check Results

### API Design

- [warn] Machine-readable, versioned contract — info.version="1.0.0" set but no versioning scheme (URL / header / media type) detected. Investigated: spec 75%, docs 50%.
- [warn] Auth declared & discoverable — No securitySchemes declared. Investigated: docs 69%, spec 49%, wellknown 0%.
- [warn] Schema coverage & depth — Only 0% of operations have documented schemas. Investigated: spec 65%.
- [pass] Security & governance hygiene — No credential-shaped strings detected in spec. Investigated: spec 100%, wellknown 0%.
- [pass] Example coverage — 100% example coverage across params + responses. Investigated: spec 100%, docs 0%.

### Developer Experience

- [pass] Self-service developer portal — Signup page at https://online.citi.com/US/ag/bank/registration/set-up-online-access; no free-tier language detected in docs/pricing. Investigated: docs 100%.
- [pass] Description completeness — 50% description completeness. Investigated: spec 100%.
- [fail] Quickstart present — No quickstart/getting-started page found at the conventional paths. Investigated: docs 0%.
- [fail] Code samples in docs — No detectable code samples across 1 sampled docs pages. Investigated: docs 0%.
- [fail] Changelog published — No changelog URL or mention found in spec metadata. Investigated: spec 0%, docs 0%.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (thecodecrate/city-state, 17 snippets). Investigated: docs 100%, sdk 100%, cli 0%.
- [warn] Docs reachable, not hard auth-gated — Server ignores Accept: text/markdown header (0/1 pages return markdown). Investigated: docs 75%.
- [warn] Crawlable / AEO — No sitemap discoverable via robots.txt or /sitemap.xml on the docs host. Investigated: wellknown 50%.
- [fail] llms.txt present, valid & comprehensive — No llms.txt found at any candidate location (https://developer.citi.com/llms.txt, https://developer.citi.com/docs/llms.txt). Investigated: docs 0%.

### Agent Understanding

- [pass] Machine-readable errors (RFC 9457) — 6 distinct 4xx/5xx response codes documented. Investigated: docs 100%, spec 50%.
- [warn] Agent-navigable, token-efficient docs — No pages support .md URLs (0/1 tested). Investigated: docs 71%.
- [warn] Operation purpose clarity — 0% of operations are agent-inferable. Investigated: spec 63%.
- [warn] Description consistency across surfaces — Mean pairwise description similarity across 2 surfaces (spec, docs) is 2% (threshold 35% for full credit).
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [fail] Docs structured data — Neither JSON-LD nor OpenGraph/meta tags detected across 1 assessed pages (1 JS-rendered). Investigated: docs 0%.

### Agent Usability

- [warn] Runnable collection with test scripts — No test scripts found in the workspace's collections. Investigated: platform 50%.
- [fail] Idempotency documented — 0% of mutating operations document idempotency. Investigated: spec 0%, docs 0%.
- [fail] Rate-limit signaling — No rate-limit response headers documented. Investigated: spec 0%, docs 0%.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.
- [skip] Sandbox separation — No surface produced evidence for this capability in this run.

## Executive Summary

Citi's API program shows strong fundamentals in API design — the contract is well-structured, typed, and secure. However, partners and their AI agents face significant friction in three areas: operational reliability (missing idempotency and rate-limit guidance), discoverability and agent-readiness (no llms.txt, no AGENTS.md, no structured docs metadata), and onboarding speed (no quickstart or code samples). Prioritize closing the operational reliability and agent-readiness gaps first, as these block partners from safely automating workflows and prevent AI agents from finding and using your APIs without manual intervention.
