Bespoke Post

Bespoke Post is a New York City direct-to-consumer men's lifestyle retailer founded in 2011 by Rishi Prabhu and Steven Szaronos. It sells curated menswear, gear and home goods through a free-to-join membership: members answer an onboarding quiz, are offered a personalized monthly "Box of Awesome" shipment they can preview, swap or skip, and buy at member pricing. Alongside third-party independent brands the company operates its own labels, including Line of Trade and Fieldworth (apparel), Halfday (travel), Wren (outdoor), Ash and Fir (home and fragrance) and Marcellin (kitchen and bar). Bespoke Post publishes no public developer portal, API documentation or machine-readable specification. It does run an internal storefront API under /api/ on its own domain and - unusually for a retailer - names eight of those paths in robots.txt with explicit Allow directives for AI agents including GPTBot, ChatGPT-User, OAI-Searchbot, ClaudeBot, anthropic-ai, PerplexityBot, meta-externalagent and cohere-ai, while disallowing /api/ to every other agent.

Bespoke Post publishes 1 API on the APIs.io network. Tagged areas include Company, E-Commerce, Retail, Subscription, and Direct to Consumer.

Bespoke Post’s developer surface includes support, engineering blog, pricing, signup flow, and 13 more developer resources.

19.6/100 emerging Agent 9/100 agent aware Full breakdown ↓
scored 2026-08-03 · rubric v0.9
1 APIs
CompanyE-CommerceRetailSubscriptionDirect to ConsumerConsumer GoodsApparelMen's Lifestyle

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-03 · rubric v0.9
Composite quality — 19.6/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 1.3 / 20
Commercial Clarity 8.9 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 8.7 / 10
Agent readiness — 9/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/bespoke-post: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Bespoke Post Storefront API

Undocumented first-party storefront API serving the bespokepost.com web experience. It is not published as a developer product: there is no portal, no reference documentation, n...

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Bespoke Post Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Bespoke Post Agentic Access

0 operations

0 operations · 0 acting

AGENTIC

Resources

Get Started 2

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: bespoke-post
name: Bespoke Post
description: 'Bespoke Post is a New York City direct-to-consumer men''s lifestyle retailer founded in 2011 by Rishi Prabhu
  and Steven Szaronos. It sells curated menswear, gear and home goods through a free-to-join membership: members answer an
  onboarding quiz, are offered a personalized monthly "Box of Awesome" shipment they can preview, swap or skip, and buy at
  member pricing. Alongside third-party independent brands the company operates its own labels, including Line of Trade and
  Fieldworth (apparel), Halfday (travel), Wren (outdoor), Ash and Fir (home and fragrance) and Marcellin (kitchen and bar).
  Bespoke Post publishes no public developer portal, API documentation or machine-readable specification. It does run an internal
  storefront API under /api/ on its own domain and - unusually for a retailer - names eight of those paths in robots.txt with
  explicit Allow directives for AI agents including GPTBot, ChatGPT-User, OAI-Searchbot, ClaudeBot, anthropic-ai, PerplexityBot,
  meta-externalagent and cohere-ai, while disallowing /api/ to every other agent.'
url: https://raw.githubusercontent.com/api-evangelist/bespoke-post/refs/heads/main/apis.yml
image: https://avatars.githubusercontent.com/u/2020234?v=4
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-02'
modified: '2026-08-02'
tags:
- Company
- E-Commerce
- Retail
- Subscription
- Direct to Consumer
- Consumer Goods
- Apparel
- Men's Lifestyle
apis:
- name: Bespoke Post Storefront API
  description: 'Undocumented first-party storefront API serving the bespokepost.com web experience. It is not published as
    a developer product: there is no portal, no reference documentation, no specification and no authentication guide. Its
    existence and eight of its paths are asserted by Bespoke Post itself in robots.txt, where they carry explicit Allow directives
    for named AI agents. The paths cover product collections, the product catalog, the current user session, carts, monthly
    box assignments, personalized "for you" assignments, user segments and the onboarding quiz questions. Endpoints sit behind
    Cloudflare bot management and returned HTTP 403 to every probe, so no response contract was observed.'
  humanURL: https://www.bespokepost.com/
  baseURL: https://www.bespokepost.com/api/
  tags:
  - E-Commerce
  - Storefront
  - Catalog
  x-status: undocumented
  x-evidence:
    source: https://www.bespokepost.com/robots.txt
    fetched: '2026-08-02'
    http_status: 200
    observed_endpoint_status: 403 (Cloudflare bot challenge)
  properties:
  - type: AgenticAccess
    url: agentic-access/bespoke-post-agentic-access.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.bespokepost.com/
- type: Support
  url: https://support.bespokepost.com/
- type: Contact
  url: https://www.bespokepost.com/contact
- type: Blog
  name: Field Guide
  url: https://www.bespokepost.com/field-guide
- type: GitHubOrganization
  url: https://github.com/bespokepost
- type: Pricing
  name: Membership
  url: https://www.bespokepost.com/subscription
- type: SignUp
  url: https://www.bespokepost.com/users/sign_up
- type: Login
  url: https://www.bespokepost.com/users/sign_in
- type: TermsOfService
  url: https://www.bespokepost.com/terms
- type: PrivacyPolicy
  url: https://www.bespokepost.com/privacy
- type: Accessibility
  url: https://www.bespokepost.com/accessibility
- type: Careers
  url: https://www.bespokepost.com/careers
- type: Press
  url: https://www.bespokepost.com/press
- type: AgenticAccess
  url: agentic-access/bespoke-post-agentic-access.yml
- type: DomainSecurity
  url: security/bespoke-post-domain-security.yml
- type: LLMsTxt
  url: llms/bespoke-post-llms.txt
- type: SecondaryMarket
  name: Forge Global
  url: https://forgeglobal.com/bespoke-post_stock/
x-enrichment:
  date: '2026-08-02'
  status: enriched
  artifacts_added: 5
  pass: local-v1
Where this information came from

This is an independent, third-party profile of Bespoke Post, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.