Up API
An independent assessment of whether the Up API specification is ready for AI-assisted integration and autonomous agents, prepared for Up Bank.
Broken for autonomous agents.
The validation engine found 1 blocking violation: Invalid callback key found.. Import tools reject the specification outright until it is fixed, so nothing downstream can be generated regardless of the other pillar scores. While this gate is open, the Standards Compliance score is capped at 40 and every AI pillar weights standards at 60% (normally 30%). Fixing the blocker in Phase 1 lifts the caps; the score projection below shows what that unlocks.
Your specification currently fails import: blocking violations make SDK, docs, and MCP generators refuse it, and the scores below are capped until they are fixed. Up API scores 36.3/100: Not ready · Grade F. The weakest pillar is Standards compliance at 23; the strongest is SDK readiness for AI at 51. We recorded 493 finding instances: 1 critical, 37 high, 129 medium, and 326 low. Functional for AI-assisted builds. Broken for autonomous agents. Every finding lives in the specification, and the roadmap in this report orders the fixes by impact; resolving them projects the score to 100/100.
What these gaps cost you in production
4 failure modes across 3 groups, each driven by your audit scores. Several are active risks today.