# UnitedHealth Group — API Agent Score

> Score: 56/100 (Grade: D) | Domain: unitedhealthgroup.com | Rubric: 1.0.0 | Checked: July 24, 2026

UnitedHealth Group scored 56/100 (D), classified "not-ai-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/unitedhealthgroup)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 56/100 (D)
- Classification: not-ai-ready

## Category Scores

- API Design: 64/100 (C)
- Developer Experience: 53/100 (D)
- Agent Discovery: 60/100 (C)
- Agent Understanding: 59/100 (D)
- Agent Usability: 48/100 (F)

## Check Results

### API Design

- [warn] Schema coverage & depth — Medium parameter complexity (avg 1.7 params/op; nested/body schemas present). Investigated: spec 83%.
- [warn] Machine-readable, versioned contract — info.version="v3" set but no versioning scheme (URL / header / media type) detected. Investigated: spec 75%, docs 50%.
- [pass] Security & governance hygiene — No credential-shaped strings detected in spec. Investigated: spec 100%, wellknown 50%.
- [fail] Auth declared & discoverable — securitySchemes declared but never applied. Investigated: spec 0%, docs 0%.
- [fail] Example coverage — 0% example coverage. Investigated: spec 0%.

### Developer Experience

- [pass] Self-service developer portal — Signup page at https://www.unitedhealthgroup.com/page-not-found.html; no free-tier language detected in docs/pricing. Investigated: docs 100%.
- [fail] Quickstart present — No quickstart/getting-started page found at the conventional paths. Investigated: docs 0%.
- [fail] Description completeness — 30% description completeness. Investigated: spec 0%.
- [fail] Changelog published — No changelog URL or mention found in spec metadata. Investigated: spec 0%, docs 0%.
- [skip] Code samples in docs — No surface produced evidence for this capability in this run.

### Agent Discovery

- [warn] llms.txt present, valid & comprehensive — 39/40 same-origin links resolve (98%); 1 broken. Investigated: docs 93%.
- [warn] Docs reachable, not hard auth-gated — 40 JavaScript redirect(s) detected across 40 pages. Investigated: docs 50%.
- [warn] Crawlable / AEO — No sitemap discoverable via robots.txt or /sitemap.xml on the docs host. Investigated: wellknown 50%.
- [fail] Registry & SDK presence — Not indexed on Context7 — agents can't pull this API's docs on demand via Context7. Investigated: docs 0%, sdk 0%, cli 0%.

### Agent Understanding

- [pass] Operation purpose clarity — 100% of operations have a clear summary + operationId an agent can select on. Investigated: spec 100%.
- [warn] Agent-navigable, token-efficient docs — No pages support .md URLs (0/40 tested). Investigated: docs 69%.
- [fail] Machine-readable errors (RFC 9457) — No 4xx/5xx response codes (or default error response) documented anywhere in the spec. Investigated: spec 0%, docs 0%.
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [skip] Docs structured data — No surface produced evidence for this capability in this run.
- [skip] Description consistency across surfaces — Only 1 surface description(s) with ≥6 tokens available; need at least 2 to compare.

### Agent Usability

- [pass] Sandbox separation — Sandbox server declared but no distinguishable test credentials in scheme descriptions. Investigated: spec 100%, docs 100%.
- [fail] Idempotency documented — 0% of mutating operations document idempotency. Investigated: spec 0%, docs 0%.
- [fail] Rate-limit signaling — No rate-limit response headers documented. Investigated: spec 0%, docs 0%.
- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.
- [skip] Pagination documented & consistent — No surface produced evidence for this capability in this run.

## Executive Summary

UnitedHealthGroup's API program shows meaningful strengths in machine-readable contract structure and schema quality, but partner outcomes are held back most severely in two areas: agents and partners cannot reliably execute or trust the API surface (missing runnable examples, idempotency guidance, rate-limit signaling, and RFC 9457 errors), and the program is largely invisible to both automated agents and self-serve partners (no registry presence, no agent instructions file, no changelog). Prioritize making the API executable and trustworthy first, then close the discoverability and onboarding gaps so partners can find, evaluate, and integrate without a sales conversation.
