New · Self-serve audits are live — real Claude Code & Cursor runs against your MCP server, SDK, or CLI →
B74/100

Static pre-check · Fri, 07 Aug 2026 06:49:52 GMT

postman.com

AI agents cannot complete initialization handshakes or access published OpenAPI specifications, blocking automated API interaction and integration.

24 pass · 4 warn · 2 fail · 12 n/a
Discovery
22.2/22.2
Accessibility
32.1/33.3
Usability
19.6/44.4
Payments
n/a

Discovery 22.2/22.2

  • API reference linked from the homepagedetailsPASS

    5 API link(s), e.g. /product/api-client/

  • Canonical URL declareddetailsPASS

    https://www.postman.com/

  • Documentation linked from the homepagedetailsPASS

    2 docs link(s), e.g. https://www.postman.com/category/developer-productivity

  • Homepage has a meta descriptiondetailsPASS

    158 characters

  • Homepage has a descriptive titledetailsPASS

    "Postman: The World's Leading API Platform | Sign Up for Free" (60 chars)

  • Open Graph tags presentdetailsPASS

    og:title and og:description present

  • robots.txt allows agent crawlersdetailsPASS

    all 6 agent crawlers may fetch /

  • robots.txt existsdetailsPASS

    HTTP 200, 201 bytes

  • robots.txt points at the sitemapdetailsPASS

    robots.txt has a Sitemap: line

  • sitemap.xml exists and parsesdetailsPASS

    26 URL(s) listed

  • Brand findable in agent searchdetailsN/A

    search-based checks are deferred — excluded from the score

  • Listed in an MCP registrydetailsN/A

    registry lookup not implemented in v1 — excluded from the score rather than guessed

Accessibility 32.1/33.3

  • Content-to-markup ratio is reasonabledetailsWARN

    ratio 0.016 — 4259 readable chars in 266013 bytes of HTML

    Fix: Most of what you serve is markup and inline script rather than content. Reduce inline payloads or server-render more text so the signal-to-noise ratio favours readers.

  • Docs are readable without JavaScriptdetailsPASS

    2900 characters of text at /docs

  • Homepage responds to an agent requestdetailsPASS

    HTTP 200 for / (agent UA)

  • Served over HTTPSdetailsPASS

    https://www.postman.com/

  • Structured data (JSON-LD) on the homepagedetailsPASS

    1 valid block(s) (ItemList)

  • llms-full.txt is publisheddetailsPASS

    HTTP 200, 100852 bytes

  • llms.txt is publisheddetailsPASS

    HTTP 200, 3413 bytes

  • Links in llms.txt resolvedetailsPASS

    5 sampled link(s) all resolve

  • llms.txt is structured markdowndetailsPASS

    has headings and markdown links

  • Serves markdown when asked for itdetailsPASS

    Accept: text/markdown → text/markdown

  • Same response for agents and browsersdetailsPASS

    both User-Agents got HTTP 200

  • Homepage has readable text without JavaScriptdetailsPASS

    4259 characters of text in the served HTML

  • No long redirect chain on the homepagedetailsPASS

    1 redirect(s)

Usability 19.6/44.4

  • MCP server completes the initialize handshakedetailsFAIL

    HTTP 401 — the endpoint requires credentials to initialize

    Fix: Let unauthenticated clients complete `initialize` and `tools/list`, and require auth only on `tools/call`. An agent that cannot see your tools cannot decide to use them.

  • OpenAPI document publisheddetailsFAIL

    /openapi.json is served but is not valid JSON

    Fix: Serve a parseable OpenAPI document at /openapi.json. What is there now cannot be read by any tooling.

  • agents.md is publisheddetailsWARN

    /agents.md returns HTML

    Fix: Serve /agents.md as markdown (text/markdown or text/plain). An HTML page here is probably your SPA catch-all route.

  • The /api root behaves predictablydetailsWARN

    /api → HTTP 200 text/html

    Fix: Serve JSON from API paths, with an accurate content-type.

  • Errors are machine-readabledetailsWARN

    a nonexistent path returned HTTP 200, not 404

    Fix: Return 404 for paths that do not exist. A 200 on a missing page makes an agent believe it found something.

  • A documentation endpoint respondsdetailsPASS

    /docs → HTTP 200

  • .well-known/mcp.json advertises an MCP serverdetailsPASS

    HTTP 200, valid JSON

  • MCP tool parameters are typed and describeddetailsN/A

    no listed MCP tools to inspect

  • Every MCP tool has a descriptiondetailsN/A

    no listed MCP tools to inspect

  • MCP server lists toolsdetailsN/A

    handshake did not complete, so tools/list was not reached

  • OpenAPI declares its auth schemedetailsN/A

    no parseable OpenAPI document

  • OpenAPI operations are describeddetailsN/A

    no parseable OpenAPI document

  • OpenAPI documents error responsesdetailsN/A

    no parseable OpenAPI document

  • OpenAPI document is structurally validdetailsN/A

    no parseable OpenAPI document

Payments not applicable — excluded from the score

  • Serves a 402 payment challengedetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

  • Declares AP2 / ACP supportdetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

  • Publishes x402 payment metadatadetailsN/A

    no agent-payment rail published — not applicable. This layer is excluded from the score rather than counted against the site.

Badge

Shows the current scan score and grade for this domain, straight from the latest static pre-check.

agent readiness badge for postman.com
[![agent ready](/api/badge/postman.com)](/score/postman.com)
<a href="/score/postman.com"><img src="/api/badge/postman.com" alt="agent readiness score" /></a>