HonestClaw
What is Agent Readiness?

Agent Readiness Score

postman.com

45 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well postman.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability13.6/24
Content Accessibility16.2/24
Bot Access Control5/12
Protocol & Capability Discovery13.3/41
Authentication & Credentials12.2/19
Documentation Quality3.5/10
Structured Data I/O1.4/13
Observable State & Reliability3.7/15
Agent Safety & Trust6.5/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepAn agent-relevant subdomain is live (api.postman.com).Detected
Canonical domaincanonical-domainRoot and www converge on www.postman.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://postman.com/robots.txt declares a sitemap. Declared sitemap https://www.postman.com/sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://postman.com/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
API existenceapi-existenceA real API surface responds at https://graphql.postman-echo.com/graphql with non-HTML JSON. (source: live)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningAPI versioning is documented at https://learning.postman.com/v11/docs/design-apis/api-builder/versioning-an-api/api-versions (the versioning scheme). To reach the top level, it would need a documented deprecation/sunset lifecycle. (source: docs)Useful

Content Accessibility

llms.txtllms-txtA curated llms.txt index is published at https://www.postman.com/llms.txt: 18 links across 5 sections.Cross-verified
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap index declares 26 child sitemaps — high crawl cost; page URL inventory is not directly observable from the index.Detected
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected
Raw content extractabilityraw-content-extractabilityReadable content is extractable without JavaScript on 2 probed surface(s) with substantial visible text.Cross-verified
Markdown twinmarkdown-twinA markdown twin is published at https://learning.postman.com/index.md alongside the docs HTML surface (https://learning.postman.com/).Parseable

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt declares explicit rules for 20 AI bot(s): oai-searchbot, chatgpt-user, perplexitybot, perplexity-user, gptbot, claudebot, anthropic-ai, claude-web, google-extended, ccbot, applebot-extended, amazonbot, meta-externalagent, meta-externalfetcher, cohere-ai, bytespider, imagesiftbot, diffbot, omgili, omgilibot.Cross-verified
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
MCP descriptormcp-descriptorInformational — not scoredA file exists at https://postman.com/.well-known/mcp.json, but it doesn't contain the fields that describe an MCP server.Detected
MCP supportmcp-supportFirst-party documentation at https://www.postman.com/product/mcp-server/ identifies the MCP endpoint https://mcp.postman.com/minimal and explains both its capabilities and how clients connect or authenticate.Cross-verified
A2A Agent Carda2a-agent-cardNo A2A Agent Card found at the standard well-known locations.Not detected
MCP Server Cardmcp-server-cardNo MCP Server Card found at the standard locations an agent would check.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.postman.com.Not detected
GraphQL surfacegraphql-surfaceA GraphQL endpoint or static GraphQL documentation is present at https://postman.com/graphql.Parseable
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
Link headerslink-headersNo RFC 8288 Link headers found on any probed response.Not detected
OpenAPI specificationopenapi-specNo OpenAPI/Swagger specification found.Not detected
SDK availabilitysdk-availabilitySDK libraries page at https://learning.postman.com/docs/postman-cli/postman-cli-sdk-gen: 0 GitHub repos, 0 registry links, 0 install commands (0 pointers).Parseable
Rate limit documentationrate-limit-docsRate limiting is mentioned at https://learning.postman.com/docs/reference/postman-api/postman-api-rate-limits, but not on a page dedicated to documenting it.Detected
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Credential managementcredential-managementCredential management is mentioned at https://www.postman.com/security/, but not on a page dedicated to documenting it.Detected
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://learning.postman.com/docs/publishing-your-api/setting-up-authentication-for-public-apis, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Auth documentationauth-documentationAuthentication is fully documented at https://learning.postman.com/docs/publishing-your-api/setting-up-authentication-for-public-apis, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified
Sandbox environmentsandbox-environmentA sandbox/testing page exists at https://learning.postman.com/docs/administration/enterprise/postman-sandbox, but it doesn't show how to obtain test credentials or a test base URL.Parseable

Documentation Quality

API reference depthapi-reference-depthAn API reference page exists at https://learning.postman.com/api-docs/api-reference, but it doesn't show parameters with example requests and responses.Parseable
Changelog presencechangelog-presenceA changelog page exists at https://www.postman.com/release-notes/, but it doesn't list dated entries describing actual changes.Parseable

Structured Data I/O

Structured data I/Ostructured-data-ioNo published structured-data contract found (no typed spec response schemas).Not detected
Machine-readable pricingmachine-readable-pricingNo machine-readable pricing endpoint found (HTML pricing pages do not qualify).Not detected
Data export APIdata-export-apiA data export page exists at https://learning.postman.com/docs/getting-started/importing-and-exporting/exporting-data, but it doesn't document a bulk/export endpoint or an export format.Parseable

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.postman.com/ (HTTP 200).Detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://learning.postman.com/docs/integrations/webhooks, but it doesn't list specific event types with their payload shape.Parseable
Error documentationerror-documentationAn error documentation page exists at https://learning.postman.com/docs/tests-and-scripts/performance-testing/performance-test-errors, but it doesn't enumerate specific error codes or a documented error response shape.Parseable
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://postman.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes one org-identity signal (social).Detected
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesAt least one legal policy page is discoverable.Detected