Waymark scored postmarkapp.com 67.9/100 (C) on 24 Aug 2026.
postmarkapp.com is blockers remain. Discovery is the strongest layer, and Access is the open one. Next: openAPI document.
FindMixed
15.2/20
11 of 17 checks passed
DoorMixed
19.2/30
11 of 22 checks passed
ToolsMixed
26.7/40
4 of 7 checks passed
Pay
N/A
No cart or pay rail — out of the denominator.
Group by
1.Can an agent discover and trust you?ROBOTSSITEMAPDISCOVERYSKILLS71/100
Whether an agent can find this origin from public files and treat it as the real one.
pass
HTTPS reachable2/2
Evidence. Homepage responded 200 over HTTPS.
Probed homepage.
pass
robots.txt present2/2
Evidence. Valid robots.txt with User-agent rules.
Probed robots.txt.
pass
XML sitemap2/2
Evidence. Found sitemap.xml or sitemap index.
failed
Well-known AI catalog0/1
Evidence. No ai-plugin.json or ai-catalog.json.
Recommended fix. Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.
failed
AGENTS.md0/1
Evidence. agents.md status 404.
Probed public URLs named in the evidence.
Recommended fix. Publish /agents.md with agent-oriented usage notes.
pass
robots.txt AI policyRequired2/2
Evidence. Named AI crawlers: GPTBot, ChatGPT-User, ClaudeBot, Google-Extended, PerplexityBot, Bytespider.
pass
Sitemap for agentsRecommended2/2
Evidence. Sitemap document fetched.
Probed sitemap.
failed
HTTP Link headerbonus0/1
Evidence. No rel=sitemap|describedby|api-catalog|alternate on homepage.
Probed homepage + sitemap.
Recommended fix. Send RFC 8288 Link headers for related machine resources.
failed
ai-plugin.jsonbonus0/1
Evidence. No /.well-known/ai-plugin.json.
Probed well-known paths.
Recommended fix. Optionally publish a plugin-style capability manifest.
n/a
API catalog linksetbonus0/2
Evidence. No public API catalog (N/A).
scanner error
Wikipedia sitelinkbonus0/4
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Wikidata official websitebonus0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
Brand official-website matchRecommended0/3
Evidence. Wikidata SPARQL The operation was aborted
Scanner error — not counted as a site fail and not in the score denominator.
pass
Public MCP registry listingbonus1/1
Evidence. Registry hit at https://glama.ai/mcp/servers?query=postmarkapp.
Probed public URLs named in the evidence.
failed
Package homepage matchbonus0/1
Evidence. No npm package homepage matching postmarkapp.com.
Probed homepage.
Recommended fix. Publish an official package whose homepage is this domain.
pass
Sitemap lastmodbonus1/1
Evidence. Sitemap has lastmod.
scanner error
related-website-setbonus0/1
Evidence. No related-website-set (N/A unless multi-origin).
Scanner error — not counted as a site fail and not in the score denominator.
scanner error
ads.txtbonus0/1
Evidence. No ads inventory (N/A).
Scanner error — not counted as a site fail and not in the score denominator.
2.Do you welcome agents?ROBOTSCRAWLBOT AUTH63/100
Whether crawlers and signed bots are allowed through rather than blocked at the door.
pass
AI crawlers not blanket-blocked2/2
Evidence. No blanket Disallow: / for common AI bots.
n/a
robots Crawl-delaybonus0/1
Evidence. No Crawl-delay (optional).
scanner error
Web Bot Auth keysRecommended0/2
Evidence. No http-message-signatures-directory.
Scanner error — not counted as a site fail and not in the score denominator.
partial
CORS / API hint0.5/1
Evidence. No CORS header or obvious API path.
Recommended fix. If you expose an API, send Access-Control-Allow-Origin for intended clients.
failed
CSP or X-Frame-Options0/1
Evidence. Neither CSP nor X-Frame-Options on homepage.
Probed homepage.
Recommended fix. Send Content-Security-Policy or X-Frame-Options.
3.Does an agent understand who you are and what you do?HTMLJSON-LDLLMS.TXTSKILLSDOCSNLWEB92/100
Whether the site explains the product in language a model can ingest.
pass
Title and description2/2
Evidence. Title and meta description present.
pass
JSON-LD structured data4/4
Evidence. application/ld+json script found.
pass
html lang attribute1/1
Evidence. html[lang] is set.
pass
JSON-LD entitiesRecommended4/4
Evidence. Recognized schema.org types in JSON-LD.
pass
JSON-LD sameAsbonus2/2
Evidence. sameAs present.
pass
Open Graph basicsbonus2/2
Evidence. Open Graph plus canonical.
pass
llms.txt2/2
Evidence. Found /llms.txt with content.
pass
llms.txt indexRecommended2/2
Evidence. llms.txt has content.
pass
llms.txt size and linksRecommended2/2
Evidence. llms.txt 28164 chars, 48 URL(s).
failed
llms-full.txtbonus0/1
Evidence. llms-full.txt status 404.
Probed public URLs named in the evidence.
Recommended fix. Optionally publish /llms-full.txt for one-shot ingest.
n/a
Section llms.txtbonus0/1
Evidence. No /docs/llms.txt.
n/a
NLWeb schemamapbonus0/1
Evidence. No schemamap (N/A unless you offer NL search).
pass
Trust pagesRecommended2/2
Evidence. Trust links found.
n/a
Speakable markupbonus0/1
Evidence. No SpeakableSpecification (N/A unless voice content).
n/a
humans.txtbonus0/1
Evidence. No /humans.txt (optional).
scanner error
security.txtRecommended0/1
Evidence. No /.well-known/security.txt Contact.
Probed well-known paths.
Scanner error — not counted as a site fail and not in the score denominator.
failed
RSS or Atom feed0/1
Evidence. No RSS/Atom link.
Recommended fix. Expose an RSS or Atom feed for machine subscribers.
n/a
RSS or Atom documentbonus0/1
Evidence. No /feed or /rss.xml document.
4.Can an agent integrate with you?LINKSSKILLSDOCSAPIOPSMCPSDK74/100
Whether there is a documented machine door into the product.
failed
OpenAPI / Swagger link0/2
Evidence. No OpenAPI/Swagger link in HTML.
Probed OpenAPI.
Recommended fix. Link to an OpenAPI or Swagger document from the homepage.
pass
Login or docs link3/3
Evidence. Login or developer docs link found.
n/a
MCP well-known card0/2
Evidence. No MCP surface (N/A).
n/a
MCP SSE / HTTP hint0/1
Evidence. No MCP/SSE hint on the homepage.
Probed homepage.
n/a
openapi.json fetchable0/0
Evidence. API surface without a fetchable OpenAPI document.
Probed OpenAPI.
pass
Webhook or API docs2/2
Evidence. Webhook or API docs mention found.
pass
Agent skills index2/2
Evidence. Skills index or mention found.
failed
OpenAPI documentRequired0/7
Evidence. OpenAPI probe.
Probed OpenAPI.
Recommended fix. Publish an OpenAPI document at a stable URL. Verify: curl -sI https://postmarkapp.com/openapi.json
pass
Public API surfaceRecommended7/7
Evidence. Docs or API paths look callable.
pass
Developer portalRecommended6/6
Evidence. Developer hub found.
n/a
MCP serverRecommended0/6
Evidence. MCP probe.
n/a
MCP server cardRecommended0/2
Evidence. No MCP surface (N/A).
pass
Agent Skills filesbonus2/2
Evidence. Skills file or index found.
pass
CLI toolRecommended3/3
Evidence. CLI mention found.
n/a
GraphQL GET hintbonus0/2
Evidence. No GraphQL surface (N/A).
n/a
OpenAPI UI pagebonus0/1
Evidence. No swagger-ui/redoc page.
n/a
OpenAPI (legacy slot)0/0
Evidence. API surface without OpenAPI.
Probed OpenAPI.
5.Is your integration well-built?APIMCPN/A
Whether the integration surface is complete enough to call with confidence.
n/a
MCP initializeRequired0/3
Evidence. No MCP card to initialize
n/a
MCP server cardRecommended0/2
Evidence. No MCP surface (N/A).
6.Can an agent use you reliably in production?MCPAPIOPS33/100
Whether errors, idempotency, and limits are visible before a call fails.
partial
Rate limit signalRecommended1/2
Evidence. API surface without a rate-limit signal.
Recommended fix. Document or send rate-limit headers on APIs.
partial
Idempotency signalRecommended1/3
Evidence. API surface without idempotency notes.
Recommended fix. Document idempotency keys for mutating calls.
partial
Machine-readable errorsRecommended1/4
Evidence. API surface without a JSON error shape.
Recommended fix. Return a JSON or problem+json error body.
n/a
Honest 404Recommended0/2
Evidence. 404 probe did not return 404.
7.Can an agent authenticate to you?SDKOAUTHAUTH.MDMCP0/100
Whether an agent can obtain access without a human in the loop.
failed
OAuth / OIDC well-known0/2
Evidence. No oauth-authorization-server or openid-configuration.
Recommended fix. Publish /.well-known/openid-configuration or oauth-authorization-server if you authenticate agents.
n/a
OAuth 2.0 surfaceRequired0/5
Evidence. No delegated-access surface (N/A).
n/a
OAuth AS metadataRequired0/3
Evidence. No AS metadata (N/A unless you run an AS).
failed
PKCE S256Required0/2
Evidence. Metadata lacks S256 PKCE.
Recommended fix. Advertise S256 in code_challenge_methods_supported.
n/a
OAuth protected resourceRecommended0/2
Evidence. No OAuth resource metadata (N/A).
n/a
Scoped permissionsRecommended0/5
Evidence. No named OAuth scopes.
n/a
auth.mdbonus0/2
Evidence. No /auth.md (optional).
failed
change-password well-knownbonus0/1
Evidence. Login surface without /.well-known/change-password.
Probed well-known paths.
Recommended fix. If users have passwords, serve /.well-known/change-password.
8.Can an agent transact with you?PRICINGX402MPPUCPACPAP233/100
Whether an agent can price, pay, or check out on a documented rail.
n/a
x402 paymentbonus0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Agentic checkout (ACP)bonus0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
ACP delegated paymentbonus0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Universal Commerce Protocolbonus0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
n/a
Machine Payments Protocolbonus0/0
Evidence. No cart/SKU/checkout and no live payment rail (Pay N/A).
partial
Pricing pageRecommended1/3
Evidence. No pricing page.
Recommended fix. Publish /pricing.
n/a
pricing.mdbonus0/2
Evidence. No /pricing.md (optional).
9.Can a user act through an agent?APPSN/A
Whether a person can finish a job through an agent-facing UI.
n/a
MCP Apps UI hintbonus0/1
Evidence. No MCP Apps hint (N/A unless you return UI).
n/a
A2A agent cardRequired0/2
Evidence. No agent-card.json (N/A unless A2A).
n/a
Web app manifestbonus0/1
Evidence. No web app manifest (N/A).
10.Can an agent operate your website directly?MARKDOWNA11YHTMLWEBMCPNLWEBLLMS.TXT33/100
Whether an agent can read and operate the site itself when there is no API or MCP.
failed
Markdown negotiationbonus0/1
Evidence. Homepage did not negotiate markdown.
Probed homepage.
Recommended fix. Respond to Accept: text/markdown with a markdown body.
failed
/index.md fallbackbonus0/1
Evidence. index.md status 404.
Probed public URLs named in the evidence.
Recommended fix. Serve a markdown homepage at /index.md.
n/a
WebMCP page toolsbonus0/1
Evidence. No in-page WebMCP (N/A).
n/a
NLWeb /askbonus0/1
Evidence. No NLWeb /ask (N/A).
pass
Agent mode viewbonus1/1
Evidence. mode=agent responded.
Probed public URLs named in the evidence.
n/a
NodeInfobonus0/1
Evidence. No nodeinfo (N/A).
n/a
oEmbed discoverybonus0/1
Evidence. No oEmbed (N/A unless embeddable).
··
About this snapshot & how to cite it
Public technical signals observed by Waymark. A score describes this snapshot; it does not guarantee that an agent will complete a task. Private and authenticated workflows are outside this scan.
Snapshot: . Cite the domain, score, scan time, and report URL. This URL serves the latest completed snapshot and can change after a rescan.