{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "apitemplate-io",
    "name": "APITemplate.io",
    "vendor": "Alphacloud Technologies Pte Ltd",
    "vendorUrl": "https://apitemplate.io",
    "kind": "http-api",
    "category": "design-assets",
    "summary": "APITemplate.io generates PDF documents and JPEG or PNG images from reusable templates filled with JSON data, and converts HTML, Markdown or a web page to PDF. Agents call its REST API with an API key.",
    "url": "https://www.anchorterminal.com/tools/apitemplate-io",
    "markdownUrl": "https://www.anchorterminal.com/tools/apitemplate-io.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/apitemplate-io.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/apitemplate-io.json",
    "license": "Proprietary service under APITemplate.io's Terms of Use. The SDK repositories have no licence file, and the Python client's `setup.py` names Apache 2.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://rest.apitemplate.io/v2",
    "packages": [],
    "auth": "api-key",
    "authNotes": "Calls send an API key in the `X-API-KEY` header, or as `Authorization: Token \u003ckey\u003e`. A browser signup at app.apitemplate.io creates the key, self-serve, and it can be regenerated under API Integration. Each team has its own key, separate from the personal one. No scopes or read-only keys were found. Direct URL image links carry a per-template `auth` code in the query string, with a quota and an expiry.",
    "pricing": "freemium",
    "pricingNotes": "The free plan gives 50 images or PDFs a month and 3 templates with no card, so an agent's owner can start without a contract. PDF-only plans run from $24 a month for 3,000 PDFs to $179 for 25,000, and image and PDF plans from $35 for 1,500 files to $179 for 20,000, billed monthly. Annual billing is up to 20 per cent less. Overage billing exists only on Enterprise plans by request, with no rate published (checked 2026-10-09).",
    "priceSummary": "$24 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "Monthly subscriptions paid through Stripe. No x402, MPP or L402 in the API description, the docs or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": 0,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://apitemplate.io/docs/",
    "openapi": "https://apitemplateio.s3.ap-southeast-1.amazonaws.com/redoc_apiv2/apitemplateiov2_api.yaml",
    "capabilities": [
      "design.templates",
      "design.render",
      "pdf.generate",
      "pdf.convert",
      "pdf.merge"
    ],
    "tags": [
      "hosted",
      "closed-source",
      "openapi",
      "no-card",
      "async-jobs",
      "webhooks",
      "images",
      "pdf",
      "regional-endpoints",
      "status-page",
      "sla"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 46.6,
      "grade": "D",
      "agentReady": false,
      "rank": 850,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 49,
        "maintenance": 11,
        "payments": 30,
        "reliability": 65,
        "schema": 52,
        "security": 53,
        "transparency": 59
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Hosted lines. Status page at status.apitemplate.io, hosted by UptimeRobot (20). Its 90-day figures load by script from a path the page's robots.txt disallows, so the history was not read and takes the unreadable-history score (5). Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account (15). HTTP 429 is documented with advice to pause before retrying, but no `Retry-After`, backoff interval or idempotency key (5). The SLA page commits to 99.9 per cent monthly availability with service credits (10). The generation API is generally available, with `get-template`, `update-template` and the e-invoice option marked experimental (10). Total 65."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 52,
          "points": 8.45,
          "reason": "A public OpenAPI 3.0.0 description of 12 operations, linked from the REST guide. It needed a tab character replaced before a strict YAML reader accepted it, and it carries slips such as `type: int` (22). No llms.txt (404) and no Markdown docs for agents (0). Parameter descriptions state defaults and interactions, while operation descriptions are one line and say nothing on when to use each (11). Flags are strings holding `1` or `0`, 3 of 31 shared parameters carry enums, and the image `overrides` body is an open object (5). Request samples in five languages and examples on 26 of 31 shared parameters, but errors are one generic object with no status codes (9). A `/v2` path with the v1 reference still online, and no changelog (5). Total 52."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "Responses are short JSON with download URLs, `export_type` chooses bytes or JSON, and `with_layer_info` is off by default (15). `limit` and `offset` on both list operations with filters by template, type, format and group. The default page is 300 records (15). Errors are a `status` and `message` pair with no codes or recovery guidance (6). No idempotency key. A `meta` reference shows in `list-objects`, which lets a caller check before retrying, and deletion is a GET request (4). Only `template_id` is required and calls are synchronous by default. The five SDK repositories are generated clients from September 2023 with placeholder install commands (9). Total 49."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 53,
          "points": 9.28,
          "reason": "One API key per account, regenerable in the console, with a separate key per team (20). The Direct URL `auth` code travels in a query string by design. It is tied to one template with a quota and an expiry and is not the API key, so we took no 10-point deduction. That is a judgement call. No scopes or read-only key, and `delete-object` runs on a GET with no confirmation. The Direct URL code is the only narrow credential (5). Calls return status and URLs, not third-party content (10). Request logs kept two weeks, visible in the console and switchable off, and `list-objects` records the caller's IP address (8). The site states a completed SOC 2 Type II audit with no auditor, period or report shown, plus a security policy page and 2FA. No security.txt (404), disclosure policy or bug bounty found (10). Total 53."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Plan prices with monthly file counts are public without a login, and no per-file or overage rate is published (10). Free plan of 50 files a month with no card (20). A person signs up in a browser to get the key (0). Total 30."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 11,
          "points": 0.96,
          "reason": "No changelog or release notes exist. The API description file was last modified on 28 September 2026 by its HTTP header, which is file metadata and not a dated release, so the recency line scores 0. No dated changelog entries in the last 90 days (0). Support by email with a stated reply within 24 hours and response times in the SLA, with no public changelog (6). Five SDK repositories, each a generated client committed once on 17 September 2023 (3). No tags, CI results or licence files in those repositories (2). Total 11."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 59,
          "points": 5.16,
          "note": "editorial 58, provenance 59",
          "reason": "Closed service under terms of use dated 8 April 2022, which can change without prior notice. The SDK repositories have no licence file (13). Privacy policy dated 21 January 2024 and a public DPA with standard contractual clauses. Request logs are kept two weeks, account data is deleted within 30 days of cancellation, and free accounts' files are purged after one year. Retention of personal data is otherwise stated only as long as reasonably needed (22). Clause 15.8 of the terms promises 60 days' written notice before a service is withdrawn, while clause 2.24 reserves the right to modify or discontinue any part with or without notice. No dated deprecation notices found (6). Eleven sub-processors named with purpose and country, 14 days' notice of new ones in the DPA, and four storage regions listed (17). Total 58."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses are short JSON with download URLs, `export_type` chooses bytes or JSON, and `with_layer_info` is off by default (15). `limit` and `offset` on both list operations with filters by template, type, format and group. The default page is 300 records (15). Errors are a `status` and `message` pair with no codes or recovery guidance (6). No idempotency key. A `meta` reference shows in `list-objects`, which lets a caller check before retrying, and deletion is a GET request (4). Only `template_id` is required and calls are synchronous by default. The five SDK repositories are generated clients from September 2023 with placeholder install commands (9). Total 49.",
          "maintenance": "No changelog or release notes exist. The API description file was last modified on 28 September 2026 by its HTTP header, which is file metadata and not a dated release, so the recency line scores 0. No dated changelog entries in the last 90 days (0). Support by email with a stated reply within 24 hours and response times in the SLA, with no public changelog (6). Five SDK repositories, each a generated client committed once on 17 September 2023 (3). No tags, CI results or licence files in those repositories (2). Total 11.",
          "payments": "No x402, MPP or L402 (0). Plan prices with monthly file counts are public without a login, and no per-file or overage rate is published (10). Free plan of 50 files a month with no card (20). A person signs up in a browser to get the key (0). Total 30.",
          "reliability": "Hosted lines. Status page at status.apitemplate.io, hosted by UptimeRobot (20). Its 90-day figures load by script from a path the page's robots.txt disallows, so the history was not read and takes the unreadable-history score (5). Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account (15). HTTP 429 is documented with advice to pause before retrying, but no `Retry-After`, backoff interval or idempotency key (5). The SLA page commits to 99.9 per cent monthly availability with service credits (10). The generation API is generally available, with `get-template`, `update-template` and the e-invoice option marked experimental (10). Total 65.",
          "schema": "A public OpenAPI 3.0.0 description of 12 operations, linked from the REST guide. It needed a tab character replaced before a strict YAML reader accepted it, and it carries slips such as `type: int` (22). No llms.txt (404) and no Markdown docs for agents (0). Parameter descriptions state defaults and interactions, while operation descriptions are one line and say nothing on when to use each (11). Flags are strings holding `1` or `0`, 3 of 31 shared parameters carry enums, and the image `overrides` body is an open object (5). Request samples in five languages and examples on 26 of 31 shared parameters, but errors are one generic object with no status codes (9). A `/v2` path with the v1 reference still online, and no changelog (5). Total 52.",
          "security": "One API key per account, regenerable in the console, with a separate key per team (20). The Direct URL `auth` code travels in a query string by design. It is tied to one template with a quota and an expiry and is not the API key, so we took no 10-point deduction. That is a judgement call. No scopes or read-only key, and `delete-object` runs on a GET with no confirmation. The Direct URL code is the only narrow credential (5). Calls return status and URLs, not third-party content (10). Request logs kept two weeks, visible in the console and switchable off, and `list-objects` records the caller's IP address (8). The site states a completed SOC 2 Type II audit with no auditor, period or report shown, plus a security policy page and 2FA. No security.txt (404), disclosure policy or bug bounty found (10). Total 53.",
          "transparency": "Closed service under terms of use dated 8 April 2022, which can change without prior notice. The SDK repositories have no licence file (13). Privacy policy dated 21 January 2024 and a public DPA with standard contractual clauses. Request logs are kept two weeks, account data is deleted within 30 days of cancellation, and free accounts' files are purged after one year. Retention of personal data is otherwise stated only as long as reasonably needed (22). Clause 15.8 of the terms promises 60 days' written notice before a service is withdrawn, while clause 2.24 reserves the right to modify or discontinue any part with or without notice. No dated deprecation notices found (6). Eleven sub-processors named with purpose and country, 14 days' notice of new ones in the DPA, and four storage regions listed (17). Total 58."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://apitemplate.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://apitemplate.io/pricing/",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference page (a viewer over the OpenAPI file)",
            "url": "https://apitemplate.io/apiv2/",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI 3.0.0 description file, read in place of the rendered reference page",
            "url": "https://apitemplateio.s3.ap-southeast-1.amazonaws.com/redoc_apiv2/apitemplateiov2_api.yaml",
            "seen": "2026-10-09"
          },
          {
            "what": "REST API guide (rate limits, regions, link to the OpenAPI file)",
            "url": "https://apitemplate.io/docs/integrations/rest-api",
            "seen": "2026-10-09"
          },
          {
            "what": "first API request guide",
            "url": "https://apitemplate.io/docs/getting-started/first-api-request",
            "seen": "2026-10-09"
          },
          {
            "what": "API key guide",
            "url": "https://apitemplate.io/docs/getting-started/get-api-key",
            "seen": "2026-10-09"
          },
          {
            "what": "Direct URL guide",
            "url": "https://apitemplate.io/docs/image-generation/direct-url",
            "seen": "2026-10-09"
          },
          {
            "what": "secure PDF generation FAQ (expiry, storage, request logs)",
            "url": "https://apitemplate.io/docs/faq/secure-pdf-generation",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of use",
            "url": "https://apitemplate.io/terms-of-use/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://apitemplate.io/privacy-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "Data Processing Agreement",
            "url": "https://apitemplate.io/data-processing-agreement/",
            "seen": "2026-10-09"
          },
          {
            "what": "data protection and security policy",
            "url": "https://apitemplate.io/data-protection-and-security-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "Service Level Agreement",
            "url": "https://apitemplate.io/service-level-agreement/",
            "seen": "2026-10-09"
          },
          {
            "what": "enterprise page (own storage, teams, 2FA)",
            "url": "https://apitemplate.io/enterprise-features/",
            "seen": "2026-10-09"
          },
          {
            "what": "FAQs",
            "url": "https://apitemplate.io/faqs/",
            "seen": "2026-10-09"
          },
          {
            "what": "status page (shell only, figures not read)",
            "url": "https://status.apitemplate.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "blog index, newest post 8 June 2026",
            "url": "https://apitemplate.io/blog/",
            "seen": "2026-10-09"
          },
          {
            "what": "Python SDK repository (shallow clone)",
            "url": "https://github.com/APITemplate-io/apitemplateio-python",
            "seen": "2026-10-09"
          },
          {
            "what": "JavaScript SDK repository (shallow clone)",
            "url": "https://github.com/APITemplate-io/apitemplateio-javascript",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (404)",
            "url": "https://apitemplate.io/.well-known/security.txt",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the status page's 90-day uptime and incident history, which loads by script from a path its robots.txt disallows",
          "unchecked: which regional hostnames resolve. The guides and the API reference disagree, and we sent no request to an API host",
          "unchecked: the SOC 2 Type II report, its auditor and period. The site states the audit and shows no document",
          "unchecked: the v1 API reference and template language pages on docs.apitemplate.io, whose robots.txt answered 403. We read no page on that host",
          "unchecked: the domain's registration date. rdap.org answered 404",
          "unchecked: GitHub stars and issue response on the SDK repositories, and whether any SDK is published to npm, PyPI or Packagist",
          "The terms of use forbid any robot, spider or other automatic device accessing the Site or Service (clause 8.1) and allow suspension for load or vulnerability testing without agreement (clause 15.4). No deduction taken. Settle this with the vendor before any probe is run",
          "Whether failed generations count against the monthly quota, and the overage rate on Enterprise plans",
          "Whether the Direct URL `auth` code should take the checklist's 10-point deduction for a secret in a query string. We took none",
          "The API description file sits on an Amazon S3 host with no robots.txt (the request for it answered 403). We read the file once, as the docs link it"
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "2026-10-09. Two vendor documentation pages disagree on regional endpoints. The first-request guide (https://apitemplate.io/docs/getting-started/first-api-request) lists `rest.apitemplate.io` as the US default with `rest-eu` and `rest-sg` hosts. The API reference and REST guide (https://apitemplate.io/docs/integrations/rest-api) list it as the Singapore default with `rest-de` and `rest-us`. The vendor says data is processed and stored in the region of the endpoint, so the conflict affects data residency. We did not test which hostnames resolve. 2 points."
      ],
      "verdict": "A public OpenAPI description covers 12 operations, with rate limits, four regional endpoints and a 99.9 per cent uptime SLA published. Each account or team has one unscoped API key, no changelog or deprecation notices were found, the SDK repositories date from September 2023, and two documentation pages name different regional hostnames.",
      "bestFor": "Owners who need invoices, certificates, reports and social images filled from templates, with HTML, URL and Markdown to PDF on the same key and a choice of storage region.",
      "strengths": [
        "OpenAPI 3.0.0 description of 12 operations is linked from the docs, with request samples in cURL, Python, PHP, Node.js and C# on the main operations",
        "Rate limits are published as 100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account",
        "Regional endpoints in Singapore, Frankfurt, N. Virginia and Sydney process and store requests and output in the region, per the API reference",
        "The SLA page commits to 99.9 per cent monthly availability for the REST API and dashboard, with service credits of 10 to 50 per cent",
        "Free plan of 50 images or PDFs a month with no card, and output can skip vendor storage with `export_type=file` or `cloud_storage=0`"
      ],
      "weaknesses": [
        "One API key per account or team with no scopes or read-only mode, and `GET /v2/delete-object` deletes a file with a GET request",
        "No changelog, release notes or dated deprecation notices were found, and the terms allow the service to change with or without notice",
        "The five SDK repositories each hold a generated client committed on 17 September 2023, with no tags, no licence file and placeholder install commands",
        "The first-request guide names `rest-eu` and `rest-sg` hostnames and a US default, while the API reference names `rest-de` and `rest-us` and a Singapore default",
        "Errors are documented as one `status` and `message` object with no status codes listed, and no idempotency key exists for generation calls",
        "The terms of use forbid any robot or other automatic device accessing the Site or Service, and bar load or vulnerability testing without agreement. This matters before any probe is run"
      ],
      "agentNotes": [
        "Send the key in the `X-API-KEY` header and pick the regional host first, because requests and output are processed and stored in that region",
        "Call `GET /v2/list-templates` with `with_layer_info=1` before `POST /v2/create-image`, so the `name` values in `overrides` match the template's elements",
        "Set `meta` to your own reference on each generation and check `GET /v2/list-objects` before retrying, since there is no idempotency key",
        "Set `expiration` in minutes (1 to 10080) or `export_type=file` for sensitive output. By default the download URL does not expire",
        "For `async=1` you must pass `webhook_url`. The callback is a GET with the result in the query string, retried three times",
        "On HTTP 429 pause and retry on your own schedule. The docs give no `Retry-After` header or backoff interval"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 46.6
        }
      ],
      "editorialScores": {
        "ergonomics": 49,
        "maintenance": 11,
        "payments": 30,
        "reliability": 65,
        "schema": 52,
        "security": 53,
        "transparency": 58
      },
      "provenanceScore": 59
    },
    "connect": {
      "http": "curl -X POST \"https://rest.apitemplate.io/v2/create-image?template_id=TEMPLATE_ID\" -H \"X-API-KEY: YOUR_API_KEY\" -H \"Content-Type: application/json\" -d '{\"overrides\": [{\"name\": \"title\", \"text\": \"Hello World\"}]}'"
    },
    "letme": {
      "capability": "https://letme.dev/design.templates",
      "tool": "https://letme.dev/apitemplate-io"
    },
    "notable": [
      "The API reference page is a viewer over an OpenAPI 3.0.0 file, which the REST guide also links for use with Postman or code generators. We read that file and not the rendered page (https://apitemplate.io/docs/integrations/rest-api)",
      "12 operations under `/v2`, among them `create-pdf`, `create-image`, `create-pdf-from-html`, `create-pdf-from-url`, `create-pdf-from-markdown`, `merge-pdfs`, `list-objects`, `delete-object`, `list-templates` and `account-information` (https://apitemplateio.s3.ap-southeast-1.amazonaws.com/redoc_apiv2/apitemplateiov2_api.yaml)",
      "`get-template` and `update-template` are marked experimental in the API description, and so is the `einvoice` option on `create-pdf` (https://apitemplateio.s3.ap-southeast-1.amazonaws.com/redoc_apiv2/apitemplateiov2_api.yaml)",
      "Direct URL builds an image from a GET request with a per-template `auth` code in the query string. The code has a quota and an expiry set in the editor, and is meant to sit in page markup (https://apitemplate.io/docs/image-generation/direct-url)",
      "Request logs are kept for two weeks by default and can be switched off under API Integration (https://apitemplate.io/docs/faq/secure-pdf-generation)",
      "The site states that APITemplate.io completed a SOC 2 Type II audit. No auditor, period or report link is given on the page (https://apitemplate.io/data-protection-and-security-policy/)",
      "Clause 8.1 of the terms of use forbids using any robot, spider or other automatic device to access any portion of the Site or Service, and clause 8.1(l) forbids sending payment card data, tax or employee IDs and health records through the service (https://apitemplate.io/terms-of-use/)",
      "The status page is hosted by UptimeRobot and draws its figures by script from a path its robots.txt disallows, so we did not read the uptime history (https://status.apitemplate.io/)",
      "The API description file was last modified on 28 September 2026 by its HTTP header. It did not parse in a strict YAML reader until a tab character on line 1143 was replaced (https://apitemplateio.s3.ap-southeast-1.amazonaws.com/redoc_apiv2/apitemplateiov2_api.yaml)"
    ],
    "area": "design-diagrams",
    "details": [
      {
        "label": "API",
        "value": "REST at `https://rest.apitemplate.io/v2/`, 12 operations. Template PDF and image generation, HTML, URL and Markdown to PDF, PDF merge, lists of templates and generated objects, object deletion and account quota"
      },
      {
        "label": "Regional endpoints",
        "value": "`rest.apitemplate.io` (Singapore, default), `rest-de` (Frankfurt), `rest-us` (N. Virginia) and `rest-au` (Sydney), plus `rest-alt`, `rest-alt-de` and `rest-alt-us`, per the API reference. Timeout 100 seconds and 4 MB payload on the first three, 30 seconds and 6 MB on Sydney and the alternatives"
      },
      {
        "label": "Read and write",
        "value": "Generation creates files. `list-objects`, `list-templates`, `get-template` and `account-information` read. `delete-object` deletes a generated file and `update-template` (experimental) replaces a PDF template's HTML, CSS and settings. No operation creates or deletes a template"
      },
      {
        "label": "Output formats",
        "value": "PDF (also PDF/A-3b), JPEG and PNG. `create-pdf` can return HTML, PNG or JPEG with `output_format`"
      },
      {
        "label": "Templates",
        "value": "PDF templates in HTML with Jinja2 or a visual editor, image templates in a drag-and-drop editor. Images are changed per request with an `overrides` array keyed by element name"
      },
      {
        "label": "Render speed",
        "value": "Synchronous by default. `async=1` returns at once and calls `webhook_url` when done. The vendor's FAQ gives 1.2 to 15 seconds a file. We did not measure it"
      },
      {
        "label": "Rate limits",
        "value": "100 requests per 10 seconds per IP address and 100 concurrent synchronous PDF requests per account. HTTP 429 when exceeded, with no `Retry-After` documented"
      },
      {
        "label": "Errors",
        "value": "One `Error` schema with `status` and `message` as the `default` response on every operation. No status codes or error codes are listed"
      },
      {
        "label": "Pagination",
        "value": "`limit` (default 300) and `offset` on `list-objects` and `list-templates`, with filters by template, transaction type, format and group"
      },
      {
        "label": "Webhooks",
        "value": "GET by default or POST to `webhook_url`, with `primary_url`, `transaction_ref`, `status` and `message` in the query string, retried three times. Custom headers can be set with `webhook_headers`. No signature is documented"
      },
      {
        "label": "Storage and retention",
        "value": "Output goes to the vendor's CDN with no expiry unless `expiration` is set (1 to 10080 minutes). `export_type=file` returns the bytes without storing them, and Enterprise plans can upload to the customer's AWS S3, Cloudflare R2 or Azure Storage. Free accounts' files are purged after one year"
      },
      {
        "label": "Free tier",
        "value": "50 images or PDFs a month and 3 templates, no card"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly availability for the REST API and dashboard, measured by the vendor's monitoring service. Credits of 10, 25 or 50 per cent, claimed within 30 days. The SLA page is dated 13 February 2020"
      },
      {
        "label": "SDKs",
        "value": "Generated clients for Python, JavaScript, PHP, Java and C# under github.com/APITemplate-io, each last committed on 17 September 2023 with no tags. The READMEs carry placeholder install commands, and no registry package was confirmed"
      },
      {
        "label": "No-code integrations",
        "value": "Zapier, Make.com, n8n, Airtable and Bubble.io, per the docs"
      },
      {
        "label": "Sub-processors",
        "value": "Eleven named in the privacy policy with purpose and country, among them Amazon (hosting), Google (storage, analytics and sign-in), Stripe, Crisp, Zoom, Zapier and Uptime Robot. The DPA promises 14 days' notice of a new one"
      }
    ],
    "unitPrices": [
      {
        "item": "PDF Basic",
        "unit": "month",
        "usd": 24,
        "note": "3,000 PDFs a month, 20 templates. $19 a month billed annually"
      },
      {
        "item": "PDF Standard",
        "unit": "month",
        "usd": 89,
        "note": "12,000 PDFs a month, 180 templates. $69 a month billed annually"
      },
      {
        "item": "PDF Enterprise",
        "unit": "month",
        "usd": 179,
        "note": "25,000 PDFs a month, unlimited templates, own storage. $139 a month billed annually"
      },
      {
        "item": "Starter (image and PDF)",
        "unit": "month",
        "usd": 35,
        "note": "1,500 images or PDFs a month, 15 templates. $29 a month billed annually"
      },
      {
        "item": "Standard (image and PDF)",
        "unit": "month",
        "usd": 89,
        "note": "9,000 images or PDFs a month, 150 templates. $69 a month billed annually"
      },
      {
        "item": "Enterprise (image and PDF)",
        "unit": "month",
        "usd": 179,
        "note": "20,000 images or PDFs a month, unlimited templates, own storage. $139 a month billed annually"
      }
    ],
    "provenance": {
      "legalEntity": "Alphacloud Technologies Pte Ltd",
      "domain": "apitemplate.io",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://apitemplate.io/terms-of-use/",
      "privacy": "https://apitemplate.io/privacy-policy/",
      "statusPage": "https://status.apitemplate.io/",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The terms of use name Alphacloud Technologies Pte Ltd, a Singapore company. The DPA gives Unique Entity Number 201902224G and an address at 50 Lakeside Drive, Singapore 648315.",
        "The terms of use are dated 8 April 2022. They are the customer contract for the service and its APIs, covering subscriptions, fees, content and termination.",
        "The privacy policy is dated 21 January 2024 and covers the websites, the app and the APIs. It holds the sub-processor list and the storage regions.",
        "A Data Processing Agreement with standard contractual clauses is at apitemplate.io/data-processing-agreement/, and an SLA dated 13 February 2020 at apitemplate.io/service-level-agreement/.",
        "The API answers at rest.apitemplate.io and regional hosts under apitemplate.io, per the API reference. We sent no request to an API host.",
        "apitemplate.io/.well-known/security.txt returns 404.",
        "The status page is hosted by UptimeRobot. Its figures load by script from a path its robots.txt disallows.",
        "No changelog or release notes page was found on the site, in the docs or in the SDK repositories.",
        "The domain's registration date was not established. rdap.org answered 404 for apitemplate.io."
      ],
      "score": 59,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Alphacloud Technologies Pte Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "apitemplate.io, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "rest.apitemplate.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.apitemplate.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://apitemplate.io/terms-of-use/",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 7218,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "provided however, that ALPHACLOUD may seek to enforce any judgment in its favor in any court of competent jurisdiction."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…INCIDENTAL, PUNITIVE, EXEMPLARY, RELIANCE, OR CONSEQUENTIAL DAMAGES OF ANY KIND, INCLUDING, BUT NOT LIMITED TO, COMPENSATION, REIMBURSEMENT OR DAMAGES IN CONNECTION WITH, ARISING OUT OF, OR RELATING TO, THE USE, OR LOSS OF USE OF, THE SERVICE, LOSS OF PROFITS, LOSS OF GOODWILL, LOSS OF DATA OR CONTENT, COST OF PROCURE…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "4.3 Each Subscription shall commence on the day purchased and shall continue, unless terminated, on a monthly or annual basis (the “Subscription Term”)."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Prices of all Services are subject to change upon 30 days notice from us.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "2.6 You may not use the Service for any illegal purpose or to violate any laws in your jurisdiction (including but not limited to copyright laws)."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Service Level Agreement"
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(b) use any “deep-link”, “page-scrape”, “robot”, “spider” or other automatic device, program, algorithm or methodology, or any comparable manual process, to access, acquire, copy, or monitor any portion of the Site or Service",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "2.24 The Company reserves the right at any time and from time to time to modify or discontinue, temporarily or permanently, any part of the Service with or without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "15.4. The Service, in its sole discretion, has the right to suspend or terminate your account and refuse any and all current or future use of the Service for any reason at any time."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "After cancellation, all data is permanently deleted from backups and logs within 30 days.",
              "quote": "Within 30 days, all data will be permanently deleted from all backups and logs."
            },
            {
              "date": "2026-10-08",
              "text": "Customers must not send certain sensitive personal information through the service, including payment card details, passwords, identity document numbers and health records.",
              "quote": "(l) provide ALPHACLOUD access to or upload or send through the Services any of the following sensitive personal information: social security numbers; passport or visa numbers; driver’s license numbers; taxpayer or employee ID; financial account or payment card information; passwords;"
            },
            {
              "date": "2026-10-08",
              "text": "A customer must start any claim under the terms within one year after the claim arises.",
              "quote": "16.3. Any cause of action arising under these Terms must be commenced by you within one (1) year after the claim or cause of action arises."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://apitemplate.io/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 4715,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Alphacloud uses Personal Data we collect to provide the Services, maintain security, monitor aggregate metrics such as total number of visitors, traffic, and demographic patterns, and track user content and users as necessary to comply with the Digital Millennium Copyright Act and other applicable laws."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will retain your information for as long as it is reasonably needed for the purposes set out in How We Use Your Personal Data and Why unless you request that we remove your Personal Data as described in Your Rights Relating to Your Personal Data."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We may share your Personal with third parties in the ways that are described in the table below."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "In the event of a corporate sale, merger, reorganization, dissolution or similar event, we may also transfer your Personal Data as part of the transferred assets without your consent or notice to you."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You also have the right to ask us to delete or remove your Personal Data where you have exercised your right to object to processing (see below)."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions about our practices or this Privacy Policy, please contact us at: hello@apitemplate.io.",
              "says": "hello@apitemplate.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/apitemplate-io.json",
    "live": {
      "slug": "apitemplate-io",
      "probe": {
        "target": "https://rest.apitemplate.io/v2",
        "method": "get",
        "lastAt": "2026-10-10T02:07:00.123977661Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 1527,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 567,
        "p95ms24h": 1551,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 22
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.apitemplate.io",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:50:05.907079503Z"
      },
      "pages": [
        {
          "url": "https://apitemplate.io/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:32:36.641195644Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a0f620060789"
        },
        {
          "url": "https://apitemplate.io/terms-of-use/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:32:39.292785112Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "d94d8af8dfe8"
        }
      ],
      "updatedAt": "2026-10-10T02:07:00.123977661Z"
    }
  }
}
