Bespoke Post Storefront API

Undocumented first-party storefront API serving the bespokepost.com web experience. It is not published as a developer product: there is no portal, no reference documentation, no specification and no authentication guide. Its existence and eight of its paths are asserted by Bespoke Post itself in robots.txt, where they carry explicit Allow directives for named AI agents. The paths cover product collections, the product catalog, the current user session, carts, monthly box assignments, personalized "for you" assignments, user segments and the onboarding quiz questions. Endpoints sit behind Cloudflare bot management and returned HTTP 403 to every probe, so no response contract was observed.

API entry from apis.yml

apis.yml Raw ↑
name: Bespoke Post Storefront API
description: 'Undocumented first-party storefront API serving the bespokepost.com web experience. It is
  not published as a developer product: there is no portal, no reference documentation, no specification
  and no authentication guide. Its existence and eight of its paths are asserted by Bespoke Post itself
  in robots.txt, where they carry explicit Allow directives for named AI agents. The paths cover product
  collections, the product catalog, the current user session, carts, monthly box assignments, personalized
  "for you" assignments, user segments and the onboarding quiz questions. Endpoints sit behind Cloudflare
  bot management and returned HTTP 403 to every probe, so no response contract was observed.'
humanURL: https://www.bespokepost.com/
baseURL: https://www.bespokepost.com/api/
tags:
- E-Commerce
- Storefront
- Catalog
x-status: undocumented
x-evidence:
  source: https://www.bespokepost.com/robots.txt
  fetched: '2026-08-02'
  http_status: 200
  observed_endpoint_status: 403 (Cloudflare bot challenge)
properties:
- type: AgenticAccess
  url: agentic-access/bespoke-post-agentic-access.yml
Where this information came from

This is an independent, third-party profile of Bespoke Post Storefront API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.