Petal

Petal is a New York-based consumer fintech that issues Visa credit cards aimed at people with limited or no credit history, underwriting applicants from their bank-account cash flow (its proprietary CashScore metric) rather than a traditional credit score alone. Its Petal 1, Petal 1 Rise and Petal 2 cards are issued by WebBank, and the business is now part of the Tilt family of consumer finance brands (Tilt Card, Inc., NMLS #2295169). Petal reaches customers through iOS and Android apps plus a web dashboard and help center. It is a direct-to-consumer card issuer: as of this profile it operates no developer program, publishes no API documentation, and exposes no machine-readable API contract on any of its public hosts.

Petal is profiled on the APIs.io network. Tagged areas include Company, Financial Services, Fintech, Credit Cards, and Consumer Finance.

Petal’s developer surface includes engineering blog, support, and 5 more developer resources.

12.9/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
0 APIs
CompanyFinancial ServicesFintechCredit CardsConsumer FinanceCredit BuildingLending

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 12.9/100 · minimal
Contract Quality 0.0 / 21
Developer Ergonomics 1.1 / 17
Commercial Clarity 3.6 / 17
Operational Transparency 0.0 / 11
Governance 0.0 / 10
Discoverability 4.9 / 9
Regulatory Posture 3.3 / 15
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Payments regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/petal: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Petal Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 1

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: petal
name: Petal
description: 'Petal is a New York-based consumer fintech that issues Visa credit cards aimed at people with limited or no
  credit history, underwriting applicants from their bank-account cash flow (its proprietary CashScore metric) rather than
  a traditional credit score alone. Its Petal 1, Petal 1 Rise and Petal 2 cards are issued by WebBank, and the business is
  now part of the Tilt family of consumer finance brands (Tilt Card, Inc., NMLS #2295169). Petal reaches customers through
  iOS and Android apps plus a web dashboard and help center. It is a direct-to-consumer card issuer: as of this profile it
  operates no developer program, publishes no API documentation, and exposes no machine-readable API contract on any of its
  public hosts.'
image: https://cdn.prod.website-files.com/636a6f81a287f5628189d717/6377fffaa265e3a2b2945444_petal-og%20(1).jpg
url: https://raw.githubusercontent.com/api-evangelist/petal/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: stub
x-tier-reason: harvest
specificationVersion: '0.20'
created: '2026-08-05'
modified: '2026-08-05'
tags:
- Company
- Financial Services
- Fintech
- Credit Cards
- Consumer Finance
- Credit Building
- Lending
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/petal-domain-security.yml
- type: Website
  url: https://www.petalcard.com/
- type: Blog
  url: https://www.petalcard.com/blog
- type: Support
  url: https://support.petalcard.com/
- type: TermsOfService
  url: https://tilt.com/terms/
- type: PrivacyPolicy
  url: https://tilt.com/privacy/
- type: LLMsTxt
  url: llms/petal-llms.txt
x-enrichment:
  date: '2026-08-05'
  status: minimal
  artifacts_added: 2
  pass: local-v1
x-coverage:
  state: none
  reason: no-developer-program
  detail: Petal is a direct-to-consumer Visa card issuer whose only integration surface is the private nginx origin behind
    its mobile apps at api.petalcard.com, which serves a bare 404 at every documented-spec path and is not accompanied by
    any developer portal, reference or SDK.
  evidence:
  - url: https://api.petalcard.com/openapi.json
    status: 404
  - url: https://www.petalcard.com/developers
    status: 404
  - url: https://developers.petalcard.com/
    status: 0
  - url: https://www.petalcard.com/llms.txt
    status: 404
  - url: https://www.petalcard.com/sitemap.xml
    status: 200
  checked: '2026-08-05'
x-secondary-market-listing: https://forgeglobal.com/petal_stock/
x-note-no-signup-pointer: registration.petalcard.com and dashboard.petalcard.com are CONSUMER cardholder application/account
  surfaces, not developer credential issuance; no SignUp/Login pointer is emitted so the rating is not credited a self-service
  developer sign-up that does not exist.