{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "akoya",
    "name": "Akoya",
    "vendor": "Akoya LLC",
    "vendorUrl": "https://akoya.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "Akoya runs a US data access network through which consumers permit apps to read their bank and brokerage accounts. Data recipients call FDX-based REST APIs for accounts, balances, transactions, customer details, statements and consent, after an OAuth consent flow.",
    "url": "https://www.anchorterminal.com/tools/akoya",
    "markdownUrl": "https://www.anchorterminal.com/tools/akoya.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/akoya.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/akoya.json",
    "license": "Proprietary service under the Akoya Terms of Use and a signed data access agreement",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://products.ddp.akoya.com",
    "packages": [],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 authorisation code grant with OpenID Connect. A person requests a Data Recipient Hub account (MFA is mandatory), registers an app and receives a client ID and secret. The consumer signs in at their own institution, picks the accounts to share, and the app exchanges the code at `/token` for an ID token and a refresh token. The ID token is the bearer token for data calls. The only scopes are `openid profile offline_access`, and what an app can read is set by its product subscriptions and the consumer's account selection. The service APIs take a 24-hour service token from separate credentials. Sandbox access is self-service. Production needs a questionnaire, a security review and a signed agreement.",
    "pricing": "paid",
    "pricingNotes": "No price is published. The pricing page names Standard (fewer than 10,000 monthly connections, self-service onboarding) and Enterprise (10,000 or more, custom pricing) without figures, and its FAQ says a set-up or implementation fee may apply. The sandbox is free and self-service with test data, so an agent's owner can start without a contract. Live data needs production approval (https://akoya.com/pricing, checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the OpenAPI specifications or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.akoya.com",
    "openapi": "https://docs.akoya.com/guides/akoya-apis-3-0-0-spec",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.identity",
      "bank.consent"
    ],
    "tags": [
      "hosted",
      "oauth",
      "openapi",
      "fdx",
      "us-only",
      "sandbox",
      "webhooks",
      "sales-led",
      "closed-source",
      "soc2"
    ],
    "lastRelease": "2026-08-05",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 48.3,
      "grade": "D",
      "agentReady": false,
      "rank": 623,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 67,
        "maintenance": 33,
        "payments": 10,
        "reliability": 28,
        "schema": 70,
        "security": 64,
        "transparency": 58
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 28,
          "points": 5.6,
          "reason": "Graded as a hosted service. No public status page was found. status.akoya.com did not connect, and the docs place network availability and provider outages inside the Data Recipient Hub, behind a login (0). No readable incident history (5). The only number is a recommended maximum of 5 calls a second on the Apps Management API, with none for the data APIs (5 of 15). The docs name 429 with code 1207 and say to slow bulk requests, and advise three retries with exponential backoff on 5xx. No Retry-After header and no idempotency key for app creation were found (8 of 15). No SLA is published. The home page's 99.9%+ network availability is a vendor claim, not a commitment (0). The v3 data APIs have been in production since 23 February 2026, with only the Tax product marked beta (10). Total 28."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). No `llms.txt` or Markdown docs. docs.akoya.com/llms.txt returns the HTML docs page (0). Each endpoint states its purpose, and guides say which product fits a use case, such as preferring customer information over `/contacts` (14 of 20). Parameters are typed and the data spec carries 73 enums, but `limit` is typed as a string and the docs warn that providers may return unknown enum values (10 of 15). The spec carries response examples, and an error reference lists codes with causes (13 of 15). The major version is in the path, with a version timeline and a changelog of eight entries since early 2025 (13 of 15). Total 70."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 67,
          "points": 10.89,
          "reason": "Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. No field selection was found (17 of 25). Link-based pagination through `links.next.href`, though a small number of providers return no `prev` link (17 of 20). Errors carry a stable `code`, a `message` and an optional `debugMessage`, with causes documented. Code 602 covers both an expired token and missing consent (15 of 20). Every data endpoint is a GET, so calls are safe to repeat, and retry advice is documented. App creation has no idempotency key (14 of 20). v3 needs two or three custom headers and a provider ID on every call, the ID token stands in for an access token, and there is no SDK, only a Postman workspace (4 of 15). Total 67."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 64,
          "points": 11.2,
          "reason": "OAuth 2.0 authorisation code grant with OpenID Connect. Tokens are issued per consumer and per app, ID tokens last 15 minutes to 24 hours, refresh tokens rotate, and `/revoke` ends a grant. Scopes are fixed, and access is narrowed by product subscriptions and the consumer's account selection (26 of 30). The data APIs are read-only, and the Hub has admin and viewer roles with mandatory MFA (17 of 20). The APIs return bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Each response carries `x-akoya-interaction-id` for tracing. No per-call log for the operator was found (4 of 15). The security page states SOC 2 Type 2 and a security review of every participant. No security.txt, disclosure policy or bug bounty was found (10 of 20). Total 64."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). The pricing page names Standard and Enterprise plans by monthly connections with no figures, and says a set-up fee may apply (0). The sandbox is free and self-service with test data and no card mentioned. There is no free live tier (10 of 20). A person requests a Data Recipient Hub account and sets up MFA, and production needs a security review and a signed agreement (0). Total 10."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 33,
          "points": 2.89,
          "reason": "The data API specification is marked \"Updated 08/05/2026\", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so the last dated change is within 90 days (20). Two dated changes in the last 90 days, short of three (0). A public changelog and a support centre with ticketing inside the Hub. No public community channel was found (8 of 15). No official SDK. A Postman workspace is the only client tooling (3 of 15). Six current OpenAPI specifications, with no packages to assess (2 of 10). Total 33."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 58,
          "points": 5.08,
          "note": "editorial 44, provenance 72",
          "reason": "Closed service. The Terms of Use are public and dated 20 December 2024, while the data access agreement that governs production is not published (12 of 30). The privacy policy of 9 June 2025 gives no retention periods. The security page says Akoya passes data through without storing consumer financial data, while the docs say tokenised account number mappings are kept in a vault. No DPA was found (12 of 30). A version timeline gives release, deprecation and sunset dates with a six-month sunset rule. The Terms of Use still allow changes without prior notice (17 of 20). The privacy policy names Google Analytics. No subprocessor list or data location was found (3 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Akoya names no regulator on the pages read (+0). Total 44."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses can be sized with `limit` (default 50), `offset`, `startTime`, `endTime` and an `accountIds` filter. No field selection was found (17 of 25). Link-based pagination through `links.next.href`, though a small number of providers return no `prev` link (17 of 20). Errors carry a stable `code`, a `message` and an optional `debugMessage`, with causes documented. Code 602 covers both an expired token and missing consent (15 of 20). Every data endpoint is a GET, so calls are safe to repeat, and retry advice is documented. App creation has no idempotency key (14 of 20). v3 needs two or three custom headers and a provider ID on every call, the ID token stands in for an access token, and there is no SDK, only a Postman workspace (4 of 15). Total 67.",
          "maintenance": "The data API specification is marked \"Updated 08/05/2026\", read as 5 August 2026, and the newest changelog entry is about 31 July 2026, so the last dated change is within 90 days (20). Two dated changes in the last 90 days, short of three (0). A public changelog and a support centre with ticketing inside the Hub. No public community channel was found (8 of 15). No official SDK. A Postman workspace is the only client tooling (3 of 15). Six current OpenAPI specifications, with no packages to assess (2 of 10). Total 33.",
          "payments": "No x402, MPP or L402 (0). The pricing page names Standard and Enterprise plans by monthly connections with no figures, and says a set-up fee may apply (0). The sandbox is free and self-service with test data and no card mentioned. There is no free live tier (10 of 20). A person requests a Data Recipient Hub account and sets up MFA, and production needs a security review and a signed agreement (0). Total 10.",
          "reliability": "Graded as a hosted service. No public status page was found. status.akoya.com did not connect, and the docs place network availability and provider outages inside the Data Recipient Hub, behind a login (0). No readable incident history (5). The only number is a recommended maximum of 5 calls a second on the Apps Management API, with none for the data APIs (5 of 15). The docs name 429 with code 1207 and say to slow bulk requests, and advise three retries with exponential backoff on 5xx. No Retry-After header and no idempotency key for app creation were found (8 of 15). No SLA is published. The home page's 99.9%+ network availability is a vendor claim, not a commitment (0). The v3 data APIs have been in production since 23 February 2026, with only the Tax product marked beta (10). Total 28.",
          "schema": "OpenAPI 3.1 specifications are published for all six APIs, as YAML code blocks to copy from docs pages with no raw file address (20 of 25). No `llms.txt` or Markdown docs. docs.akoya.com/llms.txt returns the HTML docs page (0). Each endpoint states its purpose, and guides say which product fits a use case, such as preferring customer information over `/contacts` (14 of 20). Parameters are typed and the data spec carries 73 enums, but `limit` is typed as a string and the docs warn that providers may return unknown enum values (10 of 15). The spec carries response examples, and an error reference lists codes with causes (13 of 15). The major version is in the path, with a version timeline and a changelog of eight entries since early 2025 (13 of 15). Total 70.",
          "security": "OAuth 2.0 authorisation code grant with OpenID Connect. Tokens are issued per consumer and per app, ID tokens last 15 minutes to 24 hours, refresh tokens rotate, and `/revoke` ends a grant. Scopes are fixed, and access is narrowed by product subscriptions and the consumer's account selection (26 of 30). The data APIs are read-only, and the Hub has admin and viewer roles with mandatory MFA (17 of 20). The APIs return bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Each response carries `x-akoya-interaction-id` for tracing. No per-call log for the operator was found (4 of 15). The security page states SOC 2 Type 2 and a security review of every participant. No security.txt, disclosure policy or bug bounty was found (10 of 20). Total 64.",
          "transparency": "Closed service. The Terms of Use are public and dated 20 December 2024, while the data access agreement that governs production is not published (12 of 30). The privacy policy of 9 June 2025 gives no retention periods. The security page says Akoya passes data through without storing consumer financial data, while the docs say tokenised account number mappings are kept in a vault. No DPA was found (12 of 30). A version timeline gives release, deprecation and sunset dates with a six-month sunset rule. The Terms of Use still allow changes without prior notice (17 of 20). The privacy policy names Google Analytics. No subprocessor list or data location was found (3 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Akoya names no regulator on the pages read (+0). Total 44."
        },
        "sources": [
          {
            "what": "home page with network claims",
            "url": "https://akoya.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page and FAQ",
            "url": "https://akoya.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://akoya.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Use",
            "url": "https://akoya.com/terms-of-use",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://akoya.com/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "API overview",
            "url": "https://docs.akoya.com/guides/api-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "getting started, with the first sandbox calls",
            "url": "https://docs.akoya.com/guides/getting-started",
            "seen": "2026-10-08"
          },
          {
            "what": "requirements and best practices",
            "url": "https://docs.akoya.com/guides/requirements",
            "seen": "2026-10-08"
          },
          {
            "what": "guide for production access",
            "url": "https://docs.akoya.com/guides/guide-for-production-access",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning and version timeline",
            "url": "https://docs.akoya.com/guides/api-versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "API servers",
            "url": "https://docs.akoya.com/guides/api-servers",
            "seen": "2026-10-08"
          },
          {
            "what": "API error reference",
            "url": "https://docs.akoya.com/guides/api-error-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination guide",
            "url": "https://docs.akoya.com/guides/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "headers reference",
            "url": "https://docs.akoya.com/guides/headers",
            "seen": "2026-10-08"
          },
          {
            "what": "token overview",
            "url": "https://docs.akoya.com/guides/token-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI 3.1 specification for the data APIs v3.0.0",
            "url": "https://docs.akoya.com/guides/akoya-apis-3-0-0-spec",
            "seen": "2026-10-08"
          },
          {
            "what": "Apps Management API guide",
            "url": "https://docs.akoya.com/reference/management-api",
            "seen": "2026-10-08"
          },
          {
            "what": "Notifications API guide",
            "url": "https://docs.akoya.com/reference/notifications-api",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks technical guide",
            "url": "https://docs.akoya.com/reference/webhooks",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Recipient Hub manual, My Company",
            "url": "https://docs.akoya.com/guides/hub-manual-my-company",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.akoya.com/akoya/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "v3 release note",
            "url": "https://docs.akoya.com/changelog/akoya-apis-v3-released-february-23-2026",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox data endpoint, unauthenticated request",
            "url": "https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for akoya.com",
            "url": "https://rdap.verisign.com/com/v1/domain/akoya.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether a status page exists at an address we did not try. status.akoya.com, trust.akoya.com and security.akoya.com did not connect from our network",
          "unchecked: the data access agreement that governs production use, which is sent through Docusign and not published",
          "unchecked: https://recipient.ddp.akoya.com/terms-of-use, named as the licence in the OpenAPI files, which returned a script shell",
          "The specification date \"Updated 08/05/2026\" is read in US order as 5 August 2026. Read as 8 May 2026, the newest dated change would be the changelog entry of about 31 July 2026",
          "The changelog shows relative dates only (\"69 days ago\"), so its entry dates are computed from 8 October 2026",
          "Whether the Standard plan has a list price. None is shown on the pricing page",
          "Whether section 7(b) of the Terms of Use, on automated systems, is meant to cover an AI agent calling the API under a data recipient's credentials",
          "The lead described Akoya as bank-owned. The pages read today do not state its ownership",
          "No sunset date is shown for v2 in the version timeline. The six-month rule would place it near 23 August 2026"
        ]
      },
      "negative": 0,
      "verdict": "Six OpenAPI 3.1 specifications, a free self-service sandbox and read-only data endpoints behind per-consumer OAuth tokens make the API straightforward to test. Production needs a security review and a signed agreement, no price is published, and no public status page, SLA, SDK or `llms.txt` was found.",
      "bestFor": "A US fintech that wants consumer-permissioned data over direct institution APIs in FDX format and can pass a security review.",
      "strengths": [
        "Data APIs are read-only GET endpoints, and each token covers one consumer, one app and the accounts that consumer selected",
        "OpenAPI 3.1 specifications are published for the Token, Service Token, data, Apps Management, Notifications and Consent APIs",
        "Free self-service sandbox with a test institution (`mikomo`), scripted test users and a public Postman workspace",
        "Written version policy. Breaking changes only in major versions, with a six-month sunset after deprecation",
        "Webhooks report consent revocation, consent updates and planned or unplanned outages, with three delivery attempts"
      ],
      "weaknesses": [
        "No price is published. Standard (under 10,000 monthly connections) and Enterprise are named without figures, and a set-up fee may apply",
        "Production access needs an onboarding questionnaire, a security review (SOC 2 report or questionnaire) and an agreement signed by Docusign",
        "No public status page, SLA or numeric rate limit for the data APIs was found. Availability figures sit inside the Data Recipient Hub",
        "The Terms of Use forbid using any automated system to access the network and allow changes and termination without prior notice",
        "No SDK, `llms.txt` or Markdown docs. The OpenAPI files are code blocks to copy from docs pages, not downloadable files"
      ],
      "agentNotes": [
        "Send `x-akoya-interaction-type` (USER or BATCH) and `x-akoya-last-access` on every v3 data call, plus `x-akoya-intent-type` if the app subscribes to Payments",
        "Use the `id_token` as the bearer token. The `/token` response has no `access_token` field, so generic OAuth libraries need adjusting",
        "Treat ID tokens as valid for 15 minutes, refresh on error 602, and store the new refresh token returned by every refresh",
        "Page transactions by following `links.next.href` unchanged. Set `limit`, `startTime` and `endTime` on the first call only",
        "On 429 with code 1207 slow the request rate. On 5xx retry up to three times with exponential backoff"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 48.3
        }
      ],
      "editorialScores": {
        "ergonomics": 67,
        "maintenance": 33,
        "payments": 10,
        "reliability": 28,
        "schema": 70,
        "security": 64,
        "transparency": 44
      },
      "provenanceScore": 72
    },
    "connect": {
      "http": "curl --request GET --url 'https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo' --header 'x-akoya-interaction-type: USER' --header 'x-akoya-last-access: 2025-11-24T00:00:00Z' --header 'accept: application/json' --header 'authorization: Bearer {{id_token}}'"
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/akoya"
    },
    "notable": [
      "The data APIs moved to v3 in production on 23 February 2026, a breaking change announced on 15 January 2026 that made three request headers mandatory (https://docs.akoya.com/reference/akoya-apis-v3-guide)",
      "An unauthenticated GET to `https://sandbox-products.ddp.akoya.com/accounts-info/v3/mikomo` answered 401 with `{\"code\":602, \"message\":\"Customer not authorized\"}` on 8 October 2026",
      "Section 7(b) of the Terms of Use, last updated 20 December 2024, forbids using or launching any automated system to access the network, and acting as an intermediary or aggregator (https://akoya.com/terms-of-use)",
      "Production access follows an onboarding questionnaire, a security and risk review and a data access agreement signed through Docusign (https://docs.akoya.com/guides/guide-for-production-access)",
      "The pricing page names two plans by monthly connections and gives no figures. Its FAQ says a set-up or implementation fee may apply (https://akoya.com/pricing)",
      "The Payments product returns account and routing identifiers, or tokenised account numbers, for ACH and RTP. It does not move money (https://docs.akoya.com/guides/api-overview)",
      "Akoya says it passes data through and does not store consumer financial data or login credentials, and that it holds SOC 2 Type 2 (https://akoya.com/security)",
      "The home page counts 4,500+ financial institutions and 7,500+ apps, while the fintechs page says 4,300+ and 7,000+. Both are vendor claims (https://akoya.com/)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "APIs",
        "value": "Token API v2.2.0, Service Token API v1.0.1, data APIs v3.0.0 (12 paths), Apps Management API v2.0.0, Notifications API v1.1.0, Consent API v1.1.0"
      },
      {
        "label": "Data endpoints",
        "value": "`/accounts-info`, `/balances`, `/accounts` (investments), `/taxlots`, `/customers/.../current`, `/contacts`, `/payments/.../payment-networks`, `/statements`, `/tax-forms` (beta), `/transactions`, each as `/{product}/v3/{providerId}`"
      },
      {
        "label": "Servers",
        "value": "Sandbox `sandbox-idp.ddp.akoya.com`, `sandbox-sts.ddp.akoya.com`, `sandbox-products.ddp.akoya.com`, `sandbox-api.akoya.com`. Production `idp.ddp.akoya.com`, `sts.ddp.akoya.com`, `products.ddp.akoya.com`, `api.akoya.com`"
      },
      {
        "label": "Credentials",
        "value": "Per-app client ID and secret, authorisation code valid 5 minutes, ID token (JWT) valid up to 24 hours and often 15 minutes, rotating refresh token, 24-hour service token for the service APIs"
      },
      {
        "label": "Required v3 headers",
        "value": "`x-akoya-interaction-type` (USER or BATCH), `x-akoya-last-access` (ISO 8601, UTC), `x-akoya-intent-type` (payments or nonpayments) for apps subscribed to Payments"
      },
      {
        "label": "Pagination",
        "value": "`limit` (default 50), `offset`, `startTime`, `endTime` on the first call, then `links.next.href`. A small number of providers return no `prev` link"
      },
      {
        "label": "Errors",
        "value": "JSON body with `code`, `message` and optional `debugMessage`. 602 customer not authorised, 701 account not found, 703 invalid date range, 1207 too many requests (429), 503 scheduled maintenance"
      },
      {
        "label": "Rate limits",
        "value": "A recommended maximum of 5 calls a second on the Apps Management API. No number found for the data APIs"
      },
      {
        "label": "Sandbox",
        "value": "Free and self-service through the Data Recipient Hub, test institution `mikomo`, up to 10 sandbox apps through the Apps Management API"
      },
      {
        "label": "Webhooks",
        "value": "CONSENT_REVOKED, CONSENT_UPDATED, PLANNED_OUTAGE and SERVICE events to an HTTPS callback, three delivery attempts, a sandbox test event endpoint"
      },
      {
        "label": "Versions",
        "value": "v1 sunset 2 May 2023, v2 deprecated 23 February 2026, v3 current. A deprecated version sunsets six months after deprecation"
      },
      {
        "label": "Coverage",
        "value": "United States only. The Terms of Use limit use to people located in the US"
      }
    ],
    "provenance": {
      "legalEntity": "Akoya LLC",
      "domain": "akoya.com",
      "domainRegistered": "1998-06-24",
      "endpointOnVendorDomain": true,
      "terms": "https://akoya.com/terms-of-use",
      "privacy": "https://akoya.com/privacy-policy",
      "statusPage": "",
      "changelog": "https://docs.akoya.com/akoya/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Use (last updated 20 December 2024) name Akoya LLC and govern use of the Akoya Data Access Network and akoya.com. Production use also runs under a data access agreement signed through Docusign, which is not published.",
        "The privacy policy (last updated 9 June 2025) covers the website and Akoya's products and services, and gives the address 6 Liberty Square #2381, Boston, MA 02109.",
        "The OpenAPI files name https://recipient.ddp.akoya.com/terms-of-use as their licence. That address returned a 755-byte script shell to our reader.",
        "akoya.com/.well-known/security.txt and docs.akoya.com/.well-known/security.txt both returned 404.",
        "No public status page was found. status.akoya.com did not connect, and the docs place network availability and outages inside the Data Recipient Hub, behind a login.",
        "RDAP (Verisign) gives a registration date of 1998-06-24 for akoya.com."
      ],
      "score": 72,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Akoya LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "akoya.com, registered 1998-06-24 (28 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "products.ddp.akoya.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 6,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 2 of the 8 things a reader expects",
          "points": 5.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://akoya.com/terms-of-use",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-12-20",
          "words": 3509,
          "points": 6,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: December 20, 2024",
              "says": "Last updated 2024-12-20"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms and their enforcement will be governed by the laws of the New York, without regard to conflicts of law provisions.",
              "says": "The law of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…TO THOSE BASED ON CONTRACT, TORT OR OTHERWISE, ARISING OUT OF YOUR USE OF THE DAN OR THE SITE WILL NOT EXCEED ONE HUNDRED DOLLARS ($100).",
              "says": "Capped at $100"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "(b) Akoya may, in its sole discretion, accept or reject your request to register for an Account and may disable or otherwise suspend your access to your Account or the DAN at any time for any reason or no reason whatsoever, including if Akoya suspects fraud or illegal, unauthorized, or improper conduct or for security…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Akoya may modify these Terms at any time and without prior notice.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT USE THE DAN OR THE SITE."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "The DAN and the Site may be subject to sporadic interruptions and failures for a variety of reasons beyond Akoya’s control, including third party network failures and coverage limitations, service provider uptime, and acts of God."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(iv) use or launch any automated system, including “robots,” “spiders,” or “offline readers,” to access the DAN or the Site;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Akoya may modify these Terms at any time and without prior notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Akoya may discontinue the DAN or the Site or terminate your access to all or any part thereof for any reason, without prior notice, with or without cause."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Total liability for use of the network or the site is capped at 100 US dollars.",
              "quote": "ARISING OUT OF YOUR USE OF THE DAN OR THE SITE WILL NOT EXCEED ONE HUNDRED DOLLARS ($100)."
            },
            {
              "date": "2026-10-08",
              "text": "The user grants Akoya a perpetual, irrevocable licence over data submitted through the network or site, for running them and for any other lawful purpose, and the licence survives termination.",
              "quote": "to use any such data or information as is necessary or useful in connection with the provision of the DAN or the Site and for any other lawful purpose."
            },
            {
              "date": "2026-10-08",
              "text": "Users may not act as an intermediary, aggregator or service bureau, for themselves or for a third party.",
              "quote": "(v) act as an intermediary, aggregator, or service bureau yourself or on behalf of any third party."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://akoya.com/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 1174,
          "points": 5.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "When you use the Services, we may collect your contact information (such as your name, the company you work for or represent, telephone number(s), email address), unique device and online identifiers (such as IP address, device IDs), and internet or other electronic activity information (such as browser type, web page…"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share your personal information with third party vendors that help us create and deliver the Services and improve our Services."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/akoya.json",
    "live": {
      "slug": "akoya",
      "probe": {
        "target": "https://products.ddp.akoya.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:03.241288067Z",
        "lastOk": true,
        "lastStatus": 403,
        "lastMs": 322,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 333,
        "p95ms24h": 384,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "updatedAt": "2026-10-08T21:12:03.241288067Z"
    }
  }
}
