# Kaiser Permanente — API Agent Score

> Score: 47/100 (Grade: F) | Domain: kaiserpermanente.org | Rubric: 1.0.0 | Checked: July 24, 2026

Kaiser Permanente scored 47/100 (F), classified "not-ai-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/kaiserpermanente)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 47/100 (F)
- Classification: not-ai-ready

## Category Scores

- API Design: 40/100 (F)
- Developer Experience: 66/100 (C)
- Agent Discovery: 52/100 (D)
- Agent Understanding: 55/100 (D)
- Agent Usability: 40/100 (F)

## Check Results

### API Design

- [fail] Security & governance hygiene — No security.txt at /.well-known/security.txt or /security.txt. Investigated: wellknown 0%.
- [fail] Example coverage — No detectable code samples across 1 sampled docs pages. Investigated: docs 0%.
- [skip] Machine-readable, versioned contract — No surface produced evidence for this capability in this run.
- [skip] Schema coverage & depth — No surface produced evidence for this capability in this run.
- [skip] Auth declared & discoverable — No surface produced evidence for this capability in this run.

### Developer Experience

- [pass] Self-service developer portal — Self-service signup at https://healthy.kaiserpermanente.org/register?kp_shortcut_referrer=kp.org/signup; no free tier or sandbox language detected. Investigated: docs 100%.
- [warn] Quickstart present — Quickstart page reachable (10 variants scanned starting at https://developer.kp.org/quickstart) but no runnable code sample detected in HTML or .md variant. Investigated: docs 50%.
- [fail] Code samples in docs — No detectable code samples across 1 sampled docs pages. Investigated: docs 0%.
- [skip] Description completeness — No surface produced evidence for this capability in this run.
- [skip] Changelog published — No surface produced evidence for this capability in this run.

### Agent Discovery

- [warn] Docs reachable, not hard auth-gated — 1 of 1 pages return 200 for non-existent URLs (soft 404). Investigated: docs 50%.
- [warn] llms.txt present, valid & comprehensive — No llms.txt found at any candidate location (https://developer.kp.org/llms.txt, https://developer.kp.org/docs/llms.txt). Investigated: docs 33%.
- [warn] Crawlable / AEO — Sitemap present (0 entries) but carries no lastmod values. Investigated: wellknown 75%.
- [fail] Registry & SDK presence — Not indexed on Context7 — agents can't pull this API's docs on demand via Context7. Investigated: docs 0%, sdk 0%, cli 0%.

### Agent Understanding

- [warn] Agent-navigable, token-efficient docs — No pages support .md URLs (0/1 tested). Investigated: docs 71%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [fail] Docs structured data — Neither JSON-LD nor OpenGraph/meta tags detected across 1 sampled pages — likely a CSR-only docs site. Investigated: docs 0%.
- [skip] Machine-readable errors (RFC 9457) — No surface produced evidence for this capability in this run.
- [skip] Operation purpose clarity — No surface produced evidence for this capability in this run.
- [skip] Description consistency across surfaces — Only 0 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.
- [skip] Idempotency documented — No surface produced evidence for this capability in this run.
- [skip] Rate-limit signaling — No surface produced evidence for this capability in this run.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.
- [skip] Sandbox separation — No surface produced evidence for this capability in this run.

## Executive Summary

Kaiser Permanente's API program shows some progress in documentation reachability and crawlability, but two areas demand immediate attention: API design fundamentals and agent readiness. Missing security hygiene, absent request/response examples, and no runnable collections mean partners and their AI agents cannot confidently build against your APIs — creating friction that stalls integrations and erodes trust. Prioritize hardening the contract itself (security schemes and examples) first, then layer in discoverability and agent-specific context so partners and their agents can find, understand, and execute against your APIs without a sales conversation or guesswork.
