Super.com

Super.com (formerly SnapTravel and Snapcommerce) is a consumer savings company founded in 2016 by Hussein Fazal and Henry Shi, headquartered in San Francisco with engineering roots in Toronto. Its app bundles SuperTravel hotel booking, flights, SuperShop savings, SuperCash cash back and credit building, SuperPay, and SuperRx prescription discounts, and the company reports more than $2 billion in sales processed since launch on roughly $150 million raised across seed through Series C. Its only developer-facing surface is the SnapTravel Partner Search API at api.snaptravel.com — a hotel search-and-book integration offered to business partners. No public API reference, developer portal, or machine-readable specification is published: every documentation path on the API host returns 404, no developer/docs subdomain resolves, and the www.super.com HTML surface is served behind a Cloudflare bot challenge. The company does publish an RFC 9116 security.txt naming a security contact and an invite-only Bugcrowd program.

Super.com publishes 1 API on the APIs.io network. Tagged areas include Company, Travel, Hotels, Booking, and Flights.

10.5/100 minimal ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
1 APIs
CompanyTravelHotelsBookingFlightsConsumer FinanceCash BackSavingsPrescription DiscountsMobile Applications

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 10.5/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 0.9 / 20
Commercial Clarity 0.0 / 20
Operational Transparency 2.1 / 13
Governance 0.0 / 12
Discoverability 7.6 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 3 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/supercom: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

SnapTravel Partner Search API

The partner-facing hotel search API operated by Super.com under its original SnapTravel brand. The host is live and self-identifies ("Welcome to the Partner Search API for SnapT...

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Supercom Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Supercom Vulnerability Disclosure

Bugcrowd · security.txt · contact published

SECURITY

Resources

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: supercom
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/supercom.png
name: Super.com
description: 'Super.com (formerly SnapTravel and Snapcommerce) is a consumer savings company founded in 2016 by Hussein Fazal
  and Henry Shi, headquartered in San Francisco with engineering roots in Toronto. Its app bundles SuperTravel hotel booking,
  flights, SuperShop savings, SuperCash cash back and credit building, SuperPay, and SuperRx prescription discounts, and the
  company reports more than $2 billion in sales processed since launch on roughly $150 million raised across seed through
  Series C. Its only developer-facing surface is the SnapTravel Partner Search API at api.snaptravel.com — a hotel search-and-book
  integration offered to business partners. No public API reference, developer portal, or machine-readable specification is
  published: every documentation path on the API host returns 404, no developer/docs subdomain resolves, and the www.super.com
  HTML surface is served behind a Cloudflare bot challenge. The company does publish an RFC 9116 security.txt naming a security
  contact and an invite-only Bugcrowd program.'
url: https://raw.githubusercontent.com/api-evangelist/supercom/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: stub
x-tier-reason: harvest
specificationVersion: '0.20'
created: '2026-08-05'
modified: '2026-08-05'
tags:
- Company
- Travel
- Hotels
- Booking
- Flights
- Consumer Finance
- Cash Back
- Savings
- Prescription Discounts
- Mobile Applications
apis:
- aid: supercom:snaptravel-partner-search-api
  name: SnapTravel Partner Search API
  description: 'The partner-facing hotel search API operated by Super.com under its original SnapTravel brand. The host is
    live and self-identifies ("Welcome to the Partner Search API for SnapTravel"), but the API is available only through a
    business partnership: no public reference, OpenAPI, Swagger, GraphQL SDL, or Postman collection is published at any Super.com
    or SnapTravel host.'
  humanURL: https://api.snaptravel.com/
  baseURL: https://api.snaptravel.com
  tags:
  - Hotels
  - Search
  - Travel
  - Booking
  - Partners
  x-evidence:
    fetched: '2026-08-05'
    url: https://api.snaptravel.com/
    http_status: 200
    content_type: text/html; charset=utf-8
    body: Welcome to the Partner Search API for SnapTravel
    note: /openapi.json, /openapi.yaml, /swagger.json, /api-docs, /docs, /redoc, /v1/openapi.json, /graphql, /llms.txt and
      every /.well-known/* path on this host returned 404 on 2026-08-05.
  properties: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: VulnerabilityDisclosure
  url: security/supercom-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/supercom-domain-security.yml
- type: Website
  url: https://www.super.com/
- type: GitHubOrganization
  url: https://github.com/snaptravel
- type: HelpCenter
  url: https://www.super.com/help
- type: SecurityTxt
  url: well-known/supercom-security.txt
- type: WellKnown
  url: well-known/supercom-well-known.yml
- type: LLMsTxt
  url: llms/supercom-llms.txt
- type: Security
  url: security/supercom-vulnerability-disclosure.yml
x-coverage:
  state: gated
  reason: sales-gate
  detail: api.snaptravel.com answers 200 with the plain-text line "Welcome to the Partner Search API for SnapTravel" but every
    documentation path on it 404s, no developer/docs/partner subdomain resolves for super.com, and the hotel search API is
    only obtainable through a business partnership — so there is no public reference or machine-readable spec to harvest.
  evidence:
  - url: https://api.snaptravel.com/
    status: 200
  - url: https://api.snaptravel.com/openapi.json
    status: 404
  - url: https://api.snaptravel.com/api-docs
    status: 404
  - url: https://www.super.com/
    status: 403
  checked: '2026-08-05'
x-enrichment:
  date: '2026-08-05'
  status: minimal
  artifacts_added: 5
  pass: local-v1