# Pano — API Agent Score

> Score: 62/100 (Grade: C) | Domain: pano.ai | Rubric: 1.0.0 | Checked: July 29, 2026

Pano scored 62/100 (C), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/pano)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 62/100 (C)
- Classification: partially-ready

## Category Scores

- API Design: 67/100 (C)
- Developer Experience: 78/100 (B)
- Agent Discovery: 60/100 (C)
- Agent Understanding: 40/100 (F)
- Agent Usability: 86/100 (A)

## Check Results

### API Design

- [warn] Schema coverage & depth — 0/7 (0%) enum-like params are realized as constrained types (not bare strings). Investigated: sdk 77%.
- [pass] Example coverage — README is present and includes a runnable quickstart. Investigated: sdk 100%.
- [fail] Security & governance hygiene — No security.txt at /.well-known/security.txt or /security.txt. Investigated: wellknown 0%.
- [skip] Machine-readable, versioned contract — No surface produced evidence for this capability in this run.
- [skip] Auth declared & discoverable — No surface produced evidence for this capability in this run.

### Developer Experience

- [pass] Self-service developer portal — Signup page at https://jobs.ashbyhq.com/pano-ai; no free-tier language detected in docs/pricing. Investigated: docs 100%.
- [warn] Description completeness — 489/644 operations lack a description. Investigated: sdk 24%.
- [skip] Quickstart present — No surface produced evidence for this capability in this run.
- [skip] Code samples in docs — No surface produced evidence for this capability in this run.
- [skip] Changelog published — No surface produced evidence for this capability in this run.

### Agent Discovery

- [pass] Registry & SDK presence — Indexed on Context7 (websites/paloaltonetworks_pan-os_11-1_pan-os-panorama-api, 539 snippets). Investigated: docs 100%, sdk 50%, cli 0%.
- [warn] Crawlable / AEO — Sitemap present (14 entries) but carries no lastmod values. Investigated: wellknown 50%.
- [fail] llms.txt present, valid & comprehensive — No /llms-full.txt found at the candidate origins. Investigated: docs 0%, sdk 0%.
- [skip] Docs reachable, not hard auth-gated — No surface produced evidence for this capability in this run.

### Agent Understanding

- [fail] Machine-readable errors (RFC 9457) — No single common SDK base error class was found; errors do not share one root. Investigated: sdk 0%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [skip] Operation purpose clarity — No surface produced evidence for this capability in this run.
- [skip] Agent-navigable, token-efficient docs — No surface produced evidence for this capability in this run.
- [skip] Docs structured data — No surface produced evidence for this capability in this run.
- [skip] Description consistency across surfaces — Only 0 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [pass] Idempotency documented — Built-in retry machinery is present (grep-derived). Investigated: sdk 100%.
- [pass] Sandbox separation — Sandbox environments are exposed (sandbox). Investigated: sdk 100%.
- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.
- [skip] Rate-limit signaling — No surface produced evidence for this capability in this run.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.

## Executive Summary

Pano's API program shows real strength in usability fundamentals, but two areas create serious friction for partners and AI agents today: agents cannot reliably parse errors or find operational instructions, and the program lacks the discoverable front door that modern AI-driven integration workflows require. Prioritize making errors machine-readable and publishing agent context files first — these unblock any agent attempting to build against the API — then close the discovery and security gaps to ensure partners and their agents can find, trust, and safely operate the API without a sales conversation.
