# Navan — API Agent Score

> Score: 47/100 (Grade: F) | Domain: navan.com | Rubric: 1.0.0 | Checked: September 24, 2026

Navan scored 47/100 (F), classified "not-ai-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/navan)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 47/100 (F)
- Classification: not-ai-ready

## Category Scores

- API Design: 40/100 (F)
- Developer Experience: 100/100 (A+)
- Agent Discovery: 60/100 (C)
- Agent Understanding: 40/100 (F)
- Agent Usability: 40/100 (F)

## Check Results

### API Design

- [fail] Security & governance hygiene — No security.txt found at /.well-known/security.txt or /security.txt, so there's no machine-readable security contact for agents or researchers. Investigated: wellknown 0%.
- [skip] Machine-readable, versioned contract — No surface produced evidence for this capability in this run.
- [skip] Schema coverage & depth — No surface produced evidence for this capability in this run.
- [skip] Auth declared & discoverable — No surface produced evidence for this capability in this run.
- [skip] Example coverage — No surface produced evidence for this capability in this run.

### Developer Experience

- [pass] Self-service developer portal — Signup page found at https://navan.com/get-started/demo, but no free tier or sandbox is documented in docs/pricing, so an agent may hit a paywall. Investigated: docs 100%.
- [skip] Quickstart present — No surface produced evidence for this capability in this run.
- [skip] Code samples in docs — No surface produced evidence for this capability in this run.
- [skip] Description completeness — No surface produced evidence for this capability in this run.
- [skip] Changelog published — No surface produced evidence for this capability in this run.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (openapi/app_navan_openapi_yml, 31 snippets). Investigated: docs 100%, sdk 50%, cli 0%, mcp 0%, wellknown 0%.
- [warn] Crawlable / AEO — Sitemap has 11 entries but no lastmod values, so crawlers can't tell what changed recently. Investigated: wellknown 50%.
- [fail] llms.txt present, valid & comprehensive — No llms-full.txt was found at any candidate origin, so agents can't grab your full docs in one fetch. Investigated: docs 0%.
- [skip] Docs reachable, not hard auth-gated — No surface produced evidence for this capability in this run.

### Agent Understanding

- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/, so coding agents have no ready-made setup and usage instructions. Investigated: wellknown 0%.
- [skip] Machine-readable errors (RFC 9457) — No surface produced evidence for this capability in this run.
- [skip] Operation purpose clarity — No surface produced evidence for this capability in this run.
- [skip] Agent-navigable, token-efficient docs — No surface produced evidence for this capability in this run.
- [skip] Docs structured data — No surface produced evidence for this capability in this run.
- [skip] Description consistency across surfaces — Only 0 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [fail] Runnable collection with test scripts — No public Postman workspace found for the org, so there's no runnable collection an agent can execute against. Investigated: platform 0%.
- [skip] Idempotency documented — No surface produced evidence for this capability in this run.
- [skip] Rate-limit signaling — No surface produced evidence for this capability in this run.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.
- [skip] Sandbox separation — No surface produced evidence for this capability in this run.

## Executive Summary

Navan's API program shows strength in crawlability but has critical gaps in two areas that directly affect partner and agent onboarding: agents cannot discover, understand, or safely interact with your APIs without a manual conversation, and there is no runnable surface for partners to make a first call. Closing the missing machine-readable files (security.txt, llms-full.txt, AGENTS.md) and publishing a runnable workspace should be the immediate priority, as these gaps collectively block self-serve partner adoption and prevent AI coding agents from integrating correctly.
