Postmanpostman.com

ScoredJul 27, 2026, 08:37 PM

Postman's API program shows real strengths in design and developer experience, but the two areas most critical for partner and agent success — agent understanding and agent usability — are where the program is most exposed. Agents and AI-assisted integrations cannot reliably discover, parse, or safely execute against the API without a machine-readable context file, structured documentation metadata, and a clearly separated sandbox environment.

API DesignA clean, typed, well-governed API contract agents can reason about2 pass3 warn0 fail76B
SignalPointsFindingsRationale
warnMachine-readable, versioned contractvia spec20.6/25info.version="1.0.0" set but no versioning scheme (URL / header / media type) detected. Investigated: spec 83%, cli 75%, docs 65%.A current OpenAPI version with a declared versioning scheme lets agents reason about the contract.
passSecurity & governance hygienevia spec15/15No credential-shaped strings detected in spec. Investigated: spec 100%, wellknown 100%.No leaked secrets, no critical lint violations, no OWASP API Top-10 spec smells, and a published vulnerability-disclosure channel.
warnSchema coverage & depthvia spec12.5/25Only 0% of operations have documented schemas. Investigated: spec 50%, sdk 0%.Typed, complete request/response schemas are what make agent function-calling possible.
warnAuth declared & discoverablevia cli12.5/25help mentions auth but not the exact env var. Investigated: cli 50%, docs 30%, spec 15%, wellknown 0%.Agents can only authenticate when auth is declared, scoped, and discoverable.
passExample coveragevia spec10/10100% example coverage across params + responses. Investigated: spec 100%, docs 100%, cli 100%, sdk 0%.Examples carry shape semantics schemas under-specify — for humans and agents alike.
Developer ExperienceThe context both developers and agents need to integrate fast — onboarding, code samples, complete descriptions and worked examples3 pass2 warn0 fail79B
SignalPointsFindingsRationale
passSelf-service developer portalvia docs29/29Self-service signup at https://www.postman.com/signup; no free tier or sandbox language detected. Investigated: docs 100%.Self-serve key/account creation is the fast first call for partners, with no sales gate.
passCode samples in docsvia docs18/18Code samples present on 2/13 pages across 1 language(s); broader multi-language coverage missing. Investigated: docs 100%.Multi-language samples shorten time-to-first-call.
passChangelog publishedvia spec13/13changelog documented in the docs site at https://www.postman.com/release-notes/. Investigated: spec 100%, docs 100%.A published changelog lets partners track changes without surprise.
warnQuickstart presentvia docs12.5/25Quickstart page reachable (2 variants scanned starting at https://learning.postman.com/docs/getting-started/overview/) but no runnable code sample detected in HTML or .md variant. Investigated: docs 50%.A quickstart is the fastest path from landing page to first successful call.
warnDescription completenessvia spec2.3/1528% description completeness. Investigated: spec 15%.Complete descriptions are the context humans and agents need to use endpoints.
Agent DiscoveryPartners and their agents can find your APIs — llms.txt, registries, crawlable and reachable docs3 pass0 warn0 fail100A+
SignalPointsFindingsRationale
passllms.txt present, valid & comprehensivevia docs30/30llms-full.txt reachable at https://learning.postman.com/llms-full.txt. Investigated: docs 100%.A valid, comprehensive llms.txt is the machine-readable entry point for agents.
passRegistry & SDK presencevia sdk28/28Discovered SDKs in 5 distinct languages. Investigated: sdk 100%, mcp 100%, docs 0%, cli 0%, wellknown 0%.Listing in MCP registries and publishing SDKs puts the API where agents and their tooling look.
passCrawlable / AEOvia wellknown12/12Docs paths crawlable by all monitored AI agents. Investigated: wellknown 100%.Bots allowed plus a fresh sitemap make docs findable by agent crawlers.
naDocs reachable, not hard auth-gated—/30No surface produced evidence for this capability in this run.Agents can only index and fetch docs they can reach — past auth gates and over correct HTTP semantics.
Agent UnderstandingAgents can correctly interpret your APIs — machine-readable errors, consistent descriptions, structured data, parseable docs0 pass3 warn2 fail53D
SignalPointsFindingsRationale
warnOperation purpose clarityvia spec21.3/2578% of operations are agent-inferable (target 90%+). Investigated: spec 85%.Agents select the right endpoint from its summary + operationId; clear, named operations make tool-selection reliable — the strongest driver of correct tool choice.
warnMachine-readable errors (RFC 9457)via spec5.6/28No 4xx/5xx response codes (or default error response) documented anywhere in the spec. Investigated: spec 20%, docs 15%, cli 0%.RFC 9457 problem details and a documented error-code inventory let agents parse failures without burning tokens.
warnDescription consistency across surfaces0.6/7Mean pairwise description similarity across 3 surfaces (spec, docs, sdk) is 3% (threshold 35% for full credit).Every surface tells the same story about what the product is.
failAgent instructions file (AGENTS.md)via wellknown0/10No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.An AGENTS.md gives coding agents explicit setup, auth, and usage instructions to interpret and operate the API — beyond llms.txt's link index.
failDocs structured datavia docs0/8Neither JSON-LD nor OpenGraph/meta tags detected across 3 assessed pages (3 JS-rendered). Investigated: docs 0%.Structured data (JSON-LD/schema.org) on docs pages gives agents an unambiguous parse target and is what answer engines cite. Detected on the JS-rendered head (Firecrawl) for a bounded page budget, so JS-injected JSON-LD is now caught; pages we can't render are excluded rather than failed.
naAgent-navigable, token-efficient docs—/22No surface produced evidence for this capability in this run.Server-rendered, clean, small-footprint docs are what an agent can cheaply fetch and parse correctly.
Agent UsabilityAgents have the context to use your APIs reliably, not just find them0 pass4 warn1 fail45F
SignalPointsFindingsRationale
warnIdempotency documentedvia cli6.8/27no `--dry-run` flag found. Investigated: cli 25%, spec 0%, docs 0%.Documented idempotency lets agents retry safely.
warnPagination documented & consistentvia spec5.5/222 list endpoint(s) exist but no pagination params found. Investigated: spec 25%, docs 25%.Consistent, documented pagination lets agents traverse collections.
warnRunnable collection with test scriptsvia platform4.5/9No test scripts found in the workspace's collections. Investigated: platform 50%.A public, maintained collection with assertions is runnable truth agents validate against.
warnRate-limit signalingvia spec2.2/22No rate-limit response headers documented. Investigated: spec 10%, docs 10%.Machine-readable rate-limit headers let agents throttle adaptively.
failSandbox separationvia spec0/20No sandbox/test server declared across 2 server entries; no test-key prefixes documented. Investigated: spec 0%, docs 0%.An isolated environment lets agents exercise destructive operations safely.
Resources Discovered

The public resources we found for Postman — the evidence behind the score. All discovered from public sources; nothing here requires access to your systems.

APIs analyzed10Postman API, Reverse engineering an API, Postman Echo, Nanoleaf, The Good Documentation Checklist, Import a HAR file, Intro to writing tests - with examples, jeopardy-mongo: building and testing APIs, Visualizer Feature Templates, Bitbucket Pipelines-Buildkite Run Status
Want to improve your results?