# Postman — API Agent Score

> Score: 70/100 (Grade: B) | Domain: getpostman.com | Rubric: 1.0.0 | Checked: September 15, 2026

Postman scored 70/100 (B), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/getpostman)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 70/100 (B)
- Classification: partially-ready

## Category Scores

- API Design: 78/100 (B)
- Developer Experience: 66/100 (C)
- Agent Discovery: 93/100 (A+)
- Agent Understanding: 78/100 (B)
- Agent Usability: 48/100 (F)

## Check Results

### API Design

- [warn] Machine-readable, versioned contract — The API sets a version ("1.0.0") but exposes no versioning scheme in the URL, a header, or the media type, so an agent can't pin to a specific version. Investigated: spec 93%, docs 85%, cli 75%.
- [pass] Security & governance hygiene — No credential-shaped strings detected in spec. Investigated: spec 100%, wellknown 100%.
- [warn] Schema coverage & depth — Only 2% of the 62 operations document request and response schemas, so an agent can't do function-calling against most endpoints. Investigated: spec 50%.
- [warn] Auth declared & discoverable — help mentions auth but not the exact env var. Investigated: cli 50%, docs 45%, spec 23%, wellknown 0%.
- [pass] Example coverage — 100% of parameters and responses (1403 of 1403) include example values, grounding an agent in real payload shapes. Investigated: spec 100%, cli 100%, docs 0%.

### Developer Experience

- [pass] Self-service developer portal — Self-service signup available at https://www.postman.com/signup, with a free tier or sandbox documented — an agent can onboard without contacting sales. Investigated: docs 100%.
- [pass] Changelog published — changelog is documented on the docs site at https://www.postman.com/release-notes/postman-app/, even though it isn't declared in the API spec. Investigated: spec 100%, docs 100%.
- [warn] Quickstart present — Quickstart page is reachable at https://learning.postman.com/docs/getting-started/overview/ (3 variants scanned) but has no runnable code sample in its HTML or .md variant, so there's nothing to copy and run. Investigated: docs 50%.
- [warn] Description completeness — Only 33% of operations and parameters have descriptions (41 of 62 ops, 0 of 541 params), leaving an agent to guess what most endpoints do. Investigated: spec 15%.
- [fail] Code samples in docs — No code samples detected across 3 sampled docs pages, so a coding agent gets no ready-to-use examples. Investigated: docs 0%.

### Agent Discovery

- [pass] Docs reachable, not hard auth-gated — All 1 pages are publicly accessible. Investigated: docs 100%.
- [pass] Registry & SDK presence — Indexed on Context7 (websites/documenter_getpostman_view_7907941_s1a32n38, 254 snippets). Investigated: docs 100%, sdk 0%, cli 0%.
- [warn] llms.txt present, valid & comprehensive — llms.txt covers 0/1 sitemap doc pages (0%); 1 missing. Investigated: docs 75%.
- [pass] Crawlable / AEO — robots.txt lets all monitored AI crawlers reach the docs paths. Investigated: wellknown 100%.

### Agent Understanding

- [pass] Machine-readable errors (RFC 9457) — No error responses (4xx/5xx or a catch-all default) are documented anywhere in the spec, so an agent can't anticipate or handle failures. Investigated: docs 100%, spec 58%, cli 0%.
- [warn] Operation purpose clarity — Only 78% of operations (21 of 27) have both a clear summary and a descriptive name (target 90%+), so an agent may pick the wrong endpoint for the rest. Investigated: spec 90%.
- [warn] Agent-navigable, token-efficient docs — 3 of 4 endpoints have aggressive caching or missing cache headers. Investigated: docs 85%.
- [warn] Docs structured data — JSON-LD markup on only 2 of 2 assessed pages, and coverage is sparse or dateModified is missing. Investigated: docs 50%.
- [warn] Description consistency across surfaces — Mean pairwise description similarity across 2 surfaces (spec, docs) is 1% (threshold 35% for full credit).
- [fail] Agent instructions file (AGENTS.md) — no agent-facing context artifact. Investigated: cli 0%, wellknown 0%.

### Agent Usability

- [warn] Rate-limit signaling — No rate-limit response headers are documented, so an agent can't tell when it is approaching a limit and will get throttled. Investigated: spec 40%, docs 40%.
- [warn] Idempotency documented — no `--dry-run` flag found. Investigated: cli 25%, spec 0%, docs 0%.
- [warn] Pagination documented & consistent — The 2 list endpoint(s) expose no pagination parameters, forcing an agent into all-or-nothing reads. Investigated: spec 25%, docs 25%.
- [warn] Runnable collection with test scripts — No test scripts found in the workspace's public collections, so an agent can't use them to verify API behavior. Investigated: platform 50%.
- [fail] Sandbox separation — None of the 2 declared server(s) is a sandbox/test host, and no test-key prefixes are documented, so agents can only hit production. Investigated: spec 0%, docs 0%.

## Executive Summary

Getpostman's API program shows strong agent discoverability but has two critical gaps that block safe, autonomous partner integration: there is no sandbox environment for agents to test against without hitting production, and there is no agent-facing context artifact to guide AI agents through the API's capabilities and conventions. Closing these two gaps — safe integration first, then agent context and code samples — will meaningfully accelerate partner onboarding and reduce integration risk for both human developers and AI agents.
