# Mastercard — API Agent Score

> Score: 63/100 (Grade: C) | Domain: mastercard.com | Rubric: 1.0.0 | Checked: July 24, 2026

Mastercard scored 63/100 (C), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/mastercard)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 63/100 (C)
- Classification: partially-ready

## Category Scores

- API Design: 72/100 (B)
- Developer Experience: 59/100 (D)
- Agent Discovery: 69/100 (C)
- Agent Understanding: 80/100 (A)
- Agent Usability: 45/100 (F)

## Check Results

### API Design

- [warn] Machine-readable, versioned contract — info.version="1.0.0" set but no versioning scheme (URL / header / media type) detected. Investigated: spec 75%, docs 50%.
- [warn] Schema coverage & depth — Only 0% of operations have documented schemas. Investigated: spec 67%, sdk 0%.
- [warn] Security & governance hygiene — 10 credential-shaped strings detected in spec: bearer-jwt (×10). Investigated: spec 90%, wellknown 0%.
- [pass] Example coverage — 100% example coverage across params + responses. Investigated: spec 100%, docs 100%, sdk 0%.
- [warn] Auth declared & discoverable — No securitySchemes declared. Investigated: docs 25%, spec 13%.

### Developer Experience

- [pass] Code samples in docs — Code samples in 8 language(s) across docs (top: java, javascript, csharp); 1/20 pages have ≥ 2 languages on the same page. Investigated: docs 100%.
- [pass] Description completeness — 54% description completeness. Investigated: spec 100%.
- [pass] Changelog published — Newest official SDK activity 7 day(s) ago. Investigated: sdk 100%, spec 0%, docs 0%.
- [fail] Self-service developer portal — No signup page detected across conventional paths (/signup, /sign-up, /register, /get-started, /console/signup, /dashboard/signup, /try, /try-free, /free, /free-trial, /start, /start-free). Investigated: docs 0%.
- [fail] Quickstart present — No quickstart/getting-started page found at the conventional paths. Investigated: docs 0%.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (websites/ap-gateway_mastercard_api_integrationguidelines, 5851 snippets). Investigated: docs 100%, sdk 100%, cli 0%.
- [warn] Docs reachable, not hard auth-gated — 47 of 50 sampled pages return 200 for non-existent URLs (soft 404). Investigated: docs 50%.
- [warn] llms.txt present, valid & comprehensive — No llms.txt directive found in HTML of any of 50 sampled pages. Investigated: docs 31%.
- [warn] Crawlable / AEO — Sitemap lastmod coverage 0% or newest entry older than 90 days. Investigated: wellknown 75%.

### Agent Understanding

- [pass] Machine-readable errors (RFC 9457) — No 4xx/5xx response codes (or default error response) documented anywhere in the spec. Investigated: docs 100%, spec 50%.
- [warn] Operation purpose clarity — 87% of operations are agent-inferable (target 90%+). Investigated: spec 95%.
- [warn] Agent-navigable, token-efficient docs — 50 of 50 sampled pages have content starting past 50% (worst 105%). Investigated: docs 85%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [fail] Docs structured data — Neither JSON-LD nor OpenGraph/meta tags detected across 20 sampled pages — likely a CSR-only docs site. Investigated: docs 0%.
- [skip] Description consistency across surfaces — Only 1 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [warn] Pagination documented & consistent — 2 list endpoint(s) exist but no pagination params found. Investigated: spec 57%, docs 57%.
- [warn] Runnable collection with test scripts — No test scripts found in the workspace's collections. Investigated: platform 50%.
- [warn] Idempotency documented — 0% of mutating operations document idempotency. Investigated: spec 5%, docs 5%.
- [fail] Rate-limit signaling — No rate-limit response headers documented. Investigated: spec 0%, docs 0%.
- [fail] Sandbox separation — No sandbox/test server declared across 2 server entries; no test-key prefixes documented. Investigated: spec 0%, docs 0%.

## Executive Summary

Mastercard's API program shows genuine strengths in contract quality, schema design, and documentation reachability — a solid technical foundation. However, two areas demand immediate attention: partners and their AI agents cannot safely integrate without a clearly separated sandbox environment, and the program lacks the machine-readable context files and structured signals that modern agents depend on to discover and act on your APIs without human intervention. Prioritize sandbox separation and agent-readiness signals first, then accelerate self-serve onboarding to compress the time from partner sign-up to a first successful call.
