PayPal is Good to agents.
Discry independently scored how well an AI agent can discover and understand the PayPal API from what’s public — not whether it’s usable. Below: every signal we checked, what’s costing the score, and what to change.
SCORED UNDER RUBRIC 1.2 · A full re-launch under Discry Score 2.5 — a new behavioral instrument, not comparable to these scores — is in progress.
Discovery
45% of score · 69/100Comprehension
55% of score · 84/100What we found
- PayPal provides an llms.txt with a unique markdown-access hint: appending '/md/' before '/docs/' yields markdown versions of all pages, significantly improving agent consumption.
- The robots.txt does not mention AI-specific bots (no GPTBot, ClaudeBot directives) — it neither explicitly blocks nor welcomes them, relying on the wildcard User-agent: * rule.
- PayPal has an official Agent Toolkit (paypal/agent-toolkit) with dedicated MCP server support, listed on PulseMCP and Glama — strong agent tooling ecosystem.
- Comprehensive per-API OpenAPI specs available on GitHub (paypal/paypal-rest-api-specifications) covering orders, payments, subscriptions, webhooks, and more.
- Dedicated troubleshooting section with named error pages (agreement_already_cancelled, currency_mismatch, etc.) provides specific recovery guidance for common failure modes.
What to change
Prioritized by impact on discoverability. You (or your docs platform) deploy these — Discry never touches your API.
- 01Add explicit AI bot directives to robots.txt (User-agent: GPTBot, ClaudeBot) to signal openness to agent crawling.
- 02Add llms-full.txt combining the core REST API documentation into a single comprehensive document.
- 03Add .well-known/mcp.json pointing to the official PayPal Agent Toolkit MCP server.
- 04Add AGENTS.md to the paypal/agent-toolkit or paypal-rest-api-specifications repos to guide coding agents.
- 05Consolidate the per-API OpenAPI specs into a single discoverable bundle or index document.
Execution coverage · INFORMATIONAL, UNSCORED
Whether an agent can actually complete a call and recover from errors is the deeper Audit layer — documented here, but not part of the Discry Score.
Well-documented execution characteristics including OAuth2 client credentials flow, structured JSON error responses with name/message/debug_id/details/links, dedicated rate limiting guidelines page, HATEOAS-based pagination, and idempotency key support.