{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "flinks",
    "name": "Flinks",
    "vendor": "Flinks Technology Inc. (National Bank of Canada)",
    "vendorUrl": "https://www.flinks.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "Flinks is a Canadian bank-data aggregator owned by National Bank of Canada. Its REST API and Flinks Connect widget read accounts, balances, transactions and holder details from Canadian and US institutions with the holder's consent, and start Canadian bank payments.",
    "url": "https://www.anchorterminal.com/tools/flinks",
    "markdownUrl": "https://www.anchorterminal.com/tools/flinks.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/flinks.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/flinks.json",
    "license": "Proprietary service under Flinks' Master Terms and Conditions. No open-source SDK or repository was found",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "api-key",
    "authNotes": "Two static keys issued by Flinks at onboarding. The secret key goes in the `flinks-auth-key` header of `/GenerateAuthorizeToken` and returns a single-use authorise token that expires after 15 minutes. Data endpoints take the `requestId` from `/Authorize` plus an `x-api-key` header. Neither key expires, and no scopes were found. Webhooks are signed with HMAC-SHA256 in a `flinks-authenticity-key` header. Flinks Outbound, the open banking product, uses an OAuth 2.0 authorisation code flow with a `client_id` and `client_secret` and Bearer tokens. Sandbox keys for the shared Toolbox instance are published in the docs. Production keys come from a Flinks representative after a contract.",
    "pricing": "paid",
    "pricingNotes": "Plans with a monthly minimum and a one-year term (https://www.flinks.com/pricing, checked 2026-10-08). Connect is $500 a month for 200 unique connections, $1,250 for 1,100, and custom from 20,000. Enrich is $250 a month for 100 API calls and $1,100 for 1,250. Upload is $500 a month for 20 documents and $1,500 for 100. Flinks Pay is quoted by sales. The page does not state the currency or the overage rates, and says there is no pay-as-you-go plan and no self-serve trial. The Toolbox sandbox is free, with keys published in the docs and no card.",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the ten OpenAPI files or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.flinks.com",
    "llmsTxt": "https://docs.flinks.com/llms.txt",
    "openapi": "https://docs.flinks.com/openapi.yaml",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.identity",
      "bank.payments",
      "bank.consent"
    ],
    "tags": [
      "hosted",
      "api-key",
      "openapi",
      "llms-txt",
      "webhooks",
      "sandbox",
      "canada",
      "us",
      "enterprise",
      "sales-led",
      "status-page",
      "closed-source"
    ],
    "lastRelease": "2026-09-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 52.7,
      "grade": "D",
      "agentReady": false,
      "rank": 559,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 54,
        "maintenance": 31,
        "payments": 25,
        "reliability": 53,
        "schema": 83,
        "security": 50,
        "transparency": 60
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 53,
          "points": 10.6,
          "reason": "Graded with the hosted lines. status.flinks.com on incident.io has seven product components plus one per bank, with history (20). In the 90 days to 8 October 2026 the history lists 77 incidents and two maintenance windows. 61 are named for a single institution. 16 are on Flinks' own components, among them Data Aggregation for 26 hours 45 minutes from 12 July, Enrich and the Dashboard for 44 hours from 19 August, and one on 6 August that marked Data Aggregation as a partial outage. None is labelled major. The checklist gives 20 for minor incidents only, and we score 12 of 30 because of their number and length. No rate-limit numbers are published (0). `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After. The docs give a 10-second polling interval and a 30-minute cap for 202 responses, and no idempotency keys were found (5 of 15). The Master Terms commit to best efforts at 99 per cent monthly availability, with no service credits (6 of 10). The v3 API is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. The main file marks `x-api-key` as optional while the authentication guide requires it (23 of 25). llms.txt lists 216 pages with Markdown twins, plus a skill file and a documentation MCP server (10). All 34 operations in the main file carry a description, and the guides say when to use cached mode and when not to (14 of 20). Parameters are typed with defaults, the main file has 10 enums, and `SecurityResponses` is a free-form object (10 of 15). The main file has 116 example values and the error page lists codes with how to reproduce each. The spec says the authorise token lasts 30 minutes and the guide says 15 (11 of 15). The version is in the path (v3) and the changelog has monthly entries back to September 2021 (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 54,
          "points": 8.78,
          "reason": "`WithTransactions`, `WithKYC`, `AccountsFilter` and `DaysOfTransactions` trim a response, and `/GetAccountsSummary` is a lighter call. No field selection was found (16 of 25). `/GetAccountsDetail` returns up to 365 days of transactions in one payload with no pagination. `/Institutions` takes `skip` and `take`, and the Outbound FDX paths take `offset`, `limit` and time filters (10 of 20). The error page lists 29 codes with a description and a way to reproduce each, though most sit under HTTP 401, the rate-limit code among them (14 of 20). No idempotency keys were found. Cached-mode reads can be repeated, and a completing call consumes the `requestId` (8 of 20). `RequestId` is the only required body field and defaults are stated, but a first read takes three calls plus a widget session and no official SDK was found (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 50,
          "points": 8.75,
          "reason": "A secret key and an `x-api-key`, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. The authorise token is single-use and lasts 15 minutes. Outbound has an endpoint to regenerate a client secret. A partner access token travels in the URL path of `/partneraccess/{accesstoken}`, which is not a query string, so no deduction (14 of 30). The Connect data API reads bank data and cannot move money. Flinks Pay has its own authorisation. `/DeleteCard` deletes a connection's data with no confirmation step, and credential-based connections mean Flinks stores bank logins (10 of 20). Responses carry bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). The Dashboard's Request Feed lists every request with status, `requestId` and `loginId`, with roles, 2FA and IP allow-listing for staff. No API audit log was found (8 of 15). SOC 2 Type II is stated with the report on request, the Master Terms commit to ISO 27001 audit reports, and the security page gives security@flinks.com for vulnerability reports. No security.txt or bug bounty was found (11 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "No x402, MPP or L402 (0). Plan prices are public with included volumes, from $500 a month for 200 connections. Overage rates sit in the contract and the currency is not stated (10 of 20). The Toolbox sandbox is free with no card. There is no free live tier or self-serve trial (10 of 20). Sandbox keys are published in the docs, so an agent can make test calls with no signup. Live access needs a sales contract with a one-year term (5 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 31,
          "points": 2.71,
          "reason": "The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). Two dated entries fall in the last 90 days, on 1 August and 1 September, so the line for three is not met (0). Closed service with a monthly changelog and a support portal for tickets. Response times were not sampled (8 of 15). No official SDK or package was found. We give 3 of 15 for the current skill file and documentation MCP server, a departure from the checklist. No public package or CI to assess (0 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 60,
          "points": 5.25,
          "note": "editorial 48, provenance 71",
          "reason": "Closed service with public Master Terms dated 3 August 2023 and service schedules. The terms say Flinks may modify them without prior notice (15 of 30). The Services Privacy Statement of 19 April 2024 says data is kept as long as needed for the client's service, the docs say a connection's data is kept until `/DeleteCard` is called, and the terms say end-customer data is deleted in the normal course after termination. No fixed retention periods and no public DPA were found (16 of 30). No deprecation policy was found. The changelog notes that the Pay V1 endpoint stays supported, and the terms let Flinks remove any data source at its discretion (5 of 20). Instances are hosted per country so data stays in Canada or the US, the security page names Microsoft Azure and Google Cloud, and the privacy statement lists most other service providers by category only (12 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). The privacy statement says Flinks reports suspicious Flinks Pay transactions to FINTRAC, and no registration number was found (+0)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`WithTransactions`, `WithKYC`, `AccountsFilter` and `DaysOfTransactions` trim a response, and `/GetAccountsSummary` is a lighter call. No field selection was found (16 of 25). `/GetAccountsDetail` returns up to 365 days of transactions in one payload with no pagination. `/Institutions` takes `skip` and `take`, and the Outbound FDX paths take `offset`, `limit` and time filters (10 of 20). The error page lists 29 codes with a description and a way to reproduce each, though most sit under HTTP 401, the rate-limit code among them (14 of 20). No idempotency keys were found. Cached-mode reads can be repeated, and a completing call consumes the `requestId` (8 of 20). `RequestId` is the only required body field and defaults are stated, but a first read takes three calls plus a widget session and no official SDK was found (6 of 15).",
          "maintenance": "The newest changelog entry is dated 1 September 2026, 37 days before the check (20 of 30). Two dated entries fall in the last 90 days, on 1 August and 1 September, so the line for three is not met (0). Closed service with a monthly changelog and a support portal for tickets. Response times were not sampled (8 of 15). No official SDK or package was found. We give 3 of 15 for the current skill file and documentation MCP server, a departure from the checklist. No public package or CI to assess (0 of 10).",
          "payments": "No x402, MPP or L402 (0). Plan prices are public with included volumes, from $500 a month for 200 connections. Overage rates sit in the contract and the currency is not stated (10 of 20). The Toolbox sandbox is free with no card. There is no free live tier or self-serve trial (10 of 20). Sandbox keys are published in the docs, so an agent can make test calls with no signup. Live access needs a sales contract with a one-year term (5 of 20).",
          "reliability": "Graded with the hosted lines. status.flinks.com on incident.io has seven product components plus one per bank, with history (20). In the 90 days to 8 October 2026 the history lists 77 incidents and two maintenance windows. 61 are named for a single institution. 16 are on Flinks' own components, among them Data Aggregation for 26 hours 45 minutes from 12 July, Enrich and the Dashboard for 44 hours from 19 August, and one on 6 August that marked Data Aggregation as a partial outage. None is labelled major. The checklist gives 20 for minor incidents only, and we score 12 of 30 because of their number and length. No rate-limit numbers are published (0). `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After. The docs give a 10-second polling interval and a 30-minute cap for 202 responses, and no idempotency keys were found (5 of 15). The Master Terms commit to best efforts at 99 per cent monthly availability, with no service credits (6 of 10). The v3 API is generally available (10).",
          "schema": "Ten OpenAPI 3.0 files are public, 85 operations in all, 34 in the main file. The main file marks `x-api-key` as optional while the authentication guide requires it (23 of 25). llms.txt lists 216 pages with Markdown twins, plus a skill file and a documentation MCP server (10). All 34 operations in the main file carry a description, and the guides say when to use cached mode and when not to (14 of 20). Parameters are typed with defaults, the main file has 10 enums, and `SecurityResponses` is a free-form object (10 of 15). The main file has 116 example values and the error page lists codes with how to reproduce each. The spec says the authorise token lasts 30 minutes and the guide says 15 (11 of 15). The version is in the path (v3) and the changelog has monthly entries back to September 2021 (15).",
          "security": "A secret key and an `x-api-key`, both issued by Flinks, neither expiring, with no scopes and no documented rotation for the Connect API. The authorise token is single-use and lasts 15 minutes. Outbound has an endpoint to regenerate a client secret. A partner access token travels in the URL path of `/partneraccess/{accesstoken}`, which is not a query string, so no deduction (14 of 30). The Connect data API reads bank data and cannot move money. Flinks Pay has its own authorisation. `/DeleteCard` deletes a connection's data with no confirmation step, and credential-based connections mean Flinks stores bank logins (10 of 20). Responses carry bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). The Dashboard's Request Feed lists every request with status, `requestId` and `loginId`, with roles, 2FA and IP allow-listing for staff. No API audit log was found (8 of 15). SOC 2 Type II is stated with the report on request, the Master Terms commit to ISO 27001 audit reports, and the security page gives security@flinks.com for vulnerability reports. No security.txt or bug bounty was found (11 of 20).",
          "transparency": "Closed service with public Master Terms dated 3 August 2023 and service schedules. The terms say Flinks may modify them without prior notice (15 of 30). The Services Privacy Statement of 19 April 2024 says data is kept as long as needed for the client's service, the docs say a connection's data is kept until `/DeleteCard` is called, and the terms say end-customer data is deleted in the normal course after termination. No fixed retention periods and no public DPA were found (16 of 30). No deprecation policy was found. The changelog notes that the Pay V1 endpoint stays supported, and the terms let Flinks remove any data source at its discretion (5 of 20). Instances are hosted per country so data stays in Canada or the US, the security page names Microsoft Azure and Google Cloud, and the privacy statement lists most other service providers by category only (12 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). The privacy statement says Flinks reports suspicious Flinks Pay transactions to FINTRAC, and no registration number was found (+0)."
        },
        "sources": [
          {
            "what": "docs index for agents, with the list of OpenAPI files",
            "url": "https://docs.flinks.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "main OpenAPI file (34 operations)",
            "url": "https://docs.flinks.com/openapi.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "Outbound OpenAPI file (FDX paths)",
            "url": "https://docs.flinks.com/openapi-outbound.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication reference",
            "url": "https://docs.flinks.com/guides/connect/authentication-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "testing environments and sandbox keys",
            "url": "https://docs.flinks.com/guides/getting-started/testing-environments",
            "seen": "2026-10-08"
          },
          {
            "what": "key concepts (loginId, requestId, retention)",
            "url": "https://docs.flinks.com/guides/getting-started/key-concepts",
            "seen": "2026-10-08"
          },
          {
            "what": "instances and data residency",
            "url": "https://docs.flinks.com/guides/getting-started/instances",
            "seen": "2026-10-08"
          },
          {
            "what": "retrieve account data (202 polling)",
            "url": "https://docs.flinks.com/guides/connect/retrieve-account-data",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://docs.flinks.com/api/authorize/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks guide",
            "url": "https://docs.flinks.com/guides/webhooks/introduction",
            "seen": "2026-10-08"
          },
          {
            "what": "Dashboard team management",
            "url": "https://docs.flinks.com/guides/dashboard/team-management",
            "seen": "2026-10-08"
          },
          {
            "what": "security and privacy page in the docs",
            "url": "https://docs.flinks.com/guides/security",
            "seen": "2026-10-08"
          },
          {
            "what": "documentation MCP server setup",
            "url": "https://docs.flinks.com/guides/ai/mcp-server-setup",
            "seen": "2026-10-08"
          },
          {
            "what": "skill file for AI coding assistants",
            "url": "https://docs.flinks.com/skill.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.flinks.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://www.flinks.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Terms and Conditions",
            "url": "https://www.flinks.com/terms-and-conditions",
            "seen": "2026-10-08"
          },
          {
            "what": "service schedule for connectivity, Canada",
            "url": "https://www.flinks.com/service-schedule-connectivity-canada",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statements",
            "url": "https://www.flinks.com/privacy-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.flinks.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "data safety page",
            "url": "https://www.flinks.com/data-safety",
            "seen": "2026-10-08"
          },
          {
            "what": "Connect product page",
            "url": "https://www.flinks.com/products/connect",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.flinks.com/history",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://status.flinks.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for flinks.com",
            "url": "https://rdap.verisign.com/com/v1/domain/flinks.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The pricing page shows prices with a dollar sign and no currency. Whether they are Canadian or US dollars was not established, so `unitPrices` is empty",
          "The OpenAPI file says an authorise token is valid for 30 minutes and the guides say 15. Which is right was not tested",
          "unchecked: the Dashboard (signup at dashboard.flinks.com, key rotation, roles, any audit log), which sits behind a login",
          "unchecked: who registered fin.ag, the domain the API instances answer on, and flinksapp.com for Outbound",
          "unchecked: the SOC 2 Type II report and any ISO 27001 certificate, which are on request only",
          "unchecked: whether Flinks is registered with FINTRAC as a money services business. No registration number was found on the pages read",
          "No public DPA, sub-processor list with names, or deprecation policy was found on flinks.com or docs.flinks.com",
          "The lead was right about the vendor, the docs and the interface. It did not mention that the API answers on fin.ag, a second domain"
        ]
      },
      "negative": 0,
      "verdict": "Ten public OpenAPI files, an llms.txt index with Markdown twins and published sandbox keys let an agent start without a signup. Live access needs a one-year contract from $500 a month, keys never expire, no rate-limit numbers are published, and the status page logged 77 incidents in 90 days.",
      "bestFor": "A lender or fintech with steady volume that needs Canadian bank data, income and lending attributes, PDF statements or Canadian bank payments.",
      "strengths": [
        "Ten OpenAPI 3.0 files are public at docs.flinks.com, 85 operations in all, with the main Connect and Enrich file holding 34",
        "Shared sandbox keys for the Toolbox instance are published in the docs, so test calls need no account",
        "llms.txt lists 216 pages with Markdown twins, and the docs add a skill file and a read-only documentation MCP server",
        "Plan prices are public. Connect starts at $500 a month for 200 unique connections, with no integration or platform fee",
        "Each instance is hosted in the country it serves, Canada or the US, and `/DeleteCard` deletes all data held for a connection"
      ],
      "weaknesses": [
        "Live access needs a contract with a monthly minimum and a one-year term. The pricing page says there is no pay-as-you-go plan or self-serve trial",
        "The secret key, `x-api-key` and HMAC secret do not expire, and no scopes or rotation steps were found for the Connect API",
        "No rate-limit numbers are published, and `TOO_MANY_REQUESTS` is documented under HTTP 401 with no Retry-After",
        "status.flinks.com lists 77 incidents in the 90 days to 8 October 2026, 16 of them on Flinks' own components",
        "`/GetAccountsDetail` returns the whole 90 or 365 days of transactions in one payload with no pagination, and no official SDK was found"
      ],
      "agentNotes": [
        "Call `/GenerateAuthorizeToken` with the secret key in `flinks-auth-key`, then pass the returned token to the Connect iframe or to `/Authorize`. The token is single-use and expires after 15 minutes.",
        "Send the account holder through Flinks Connect in a browser. The API alone cannot complete a first bank login, and sandbox iframes need `demo=true`.",
        "Store the `loginId`. Call `/Authorize` with it and `MostRecentCached: true` for a new `requestId` each session, because `/GetAccountsDetail` consumes the `requestId`.",
        "On a 202 from `/GetAccountsDetail`, poll `/GetAccountsDetailAsync` every 10 seconds for at most 30 minutes, or ask support to enable webhooks.",
        "Route each end user to the instance for their country. A `loginId` from the Canadian instance is not valid on the US one."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 52.7
        }
      ],
      "editorialScores": {
        "ergonomics": 54,
        "maintenance": 31,
        "payments": 25,
        "reliability": 53,
        "schema": 83,
        "security": 50,
        "transparency": 48
      },
      "provenanceScore": 71
    },
    "connect": {
      "http": "curl --request POST \\\n  --url https://toolbox-api.private.fin.ag/v3/{customerId}/BankingServices/GenerateAuthorizeToken \\\n  --header 'Content-Type: application/json' \\\n  --header 'flinks-auth-key: YOUR_SECRET_KEY'",
      "claudeCode": "claude mcp add flinks --transport http https://docs.flinks.com/mcp"
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/flinks"
    },
    "notable": [
      "The docs publish shared sandbox credentials for the Toolbox instance at https://toolbox-api.private.fin.ag, with a test bank named Flinks Capital and test users such as `Greatday` (https://docs.flinks.com/guides/getting-started/testing-environments)",
      "Ten OpenAPI 3.0 files are linked from llms.txt, among them `openapi.yaml` (34 operations), `openapi-outbound.yaml` (19, FDX version 5 paths) and five for Flinks Pay (https://docs.flinks.com/llms.txt)",
      "Flinks Connect uses credential-based access, where the account holder types online banking credentials into the widget, and OAuth where an institution supports it. The Connect product page says OAuth covers 9 of the 10 largest US banks (https://www.flinks.com/products/connect)",
      "A `loginId` is permanent and Flinks keeps the stored credentials, holder details and accounts until `/DeleteCard` is called (https://docs.flinks.com/guides/getting-started/key-concepts)",
      "The docs site has an MCP server at https://docs.flinks.com/mcp with two read-only tools that search and read the documentation. It does not call the Flinks API (https://docs.flinks.com/guides/ai/mcp-server-setup)",
      "A skill file for AI coding assistants at https://docs.flinks.com/skill.md summarises the integration flow in one file (https://docs.flinks.com/guides/ai/skill)",
      "The Master Terms and Conditions, last updated 3 August 2023, commit Flinks to best efforts at 99 per cent monthly availability and let Flinks modify the terms without prior notice (https://www.flinks.com/terms-and-conditions)",
      "The OpenAPI file says an authorise token is valid for 30 minutes, while the authentication guide and the skill file say 15 minutes (https://docs.flinks.com/openapi.yaml, https://docs.flinks.com/guides/connect/authentication-reference)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST over HTTPS, TLS 1.2 or later, at https://{instance}-api.private.fin.ag/v3/{customerId}/. One instance per customer and country. The main OpenAPI file lists 34 operations"
      },
      {
        "label": "Data endpoints",
        "value": "`/GetAccountsSummary`, `/GetAccountsDetail` (accounts, balances, transactions, holder name, address, email and phone), `/GetStatements` (bank-issued PDF statements), `/Institutions`, `/FieldMatch` for identity checks"
      },
      {
        "label": "Consent",
        "value": "The account holder connects in the Flinks Connect iframe, with bank credentials or the institution's OAuth flow. The connection has no expiry. `/DeleteCard` removes the stored credentials, holder details and account data. Flinks Outbound has `/api/v1/revoke`"
      },
      {
        "label": "Sessions",
        "value": "Authorise token single-use, 15 minutes. `requestId` ends after 8 minutes of inactivity or 30 minutes of processing, or when `/GetAccountsDetail`, `/GetAccountsDetailAsync` or `/GetStatements` completes"
      },
      {
        "label": "Transactions",
        "value": "Posted transactions only, `DaysOfTransactions` of `Days90` or `Days365`, in one payload. `WithTransactions`, `WithKYC` and `AccountsFilter` trim the response"
      },
      {
        "label": "Async",
        "value": "`/GetAccountsDetail` answers 202 while data is processed. Poll `/GetAccountsDetailAsync` every 10 seconds, at most 30 minutes, or receive a webhook"
      },
      {
        "label": "Rate limits",
        "value": "No numbers published. `TOO_MANY_REQUESTS` is listed under HTTP 401"
      },
      {
        "label": "Enrich",
        "value": "Attributes endpoints for income, lending, credit risk and business analysis, and `/GetCategorization`. Flinks says 4,500+ attributes"
      },
      {
        "label": "Payments",
        "value": "Flinks Pay, Canada only. Session-based APIs for EFT (pre-authorised debit), Guaranteed EFT and Interac e-Transfer Request Money, with their own `/Authorize` and Bearer token"
      },
      {
        "label": "Open banking",
        "value": "Flinks Outbound at https://ob.flinksapp.com, OAuth 2.0 with FDX version 5 paths for customers, accounts, transactions and statements, paged with `offset` and `limit`"
      },
      {
        "label": "Sandbox",
        "value": "Shared Toolbox instance at https://toolbox-api.private.fin.ag with published keys, the Flinks Capital test bank and test users for MFA and error cases. Webhooks cannot be tested there"
      },
      {
        "label": "Webhooks",
        "value": "Enabled by a support ticket. HMAC-SHA256 signature in `flinks-authenticity-key`. Up to 10 retries, 30 minutes apart"
      },
      {
        "label": "Coverage",
        "value": "Canada and the United States. Flinks says 15,000+ financial institutions across North America"
      },
      {
        "label": "Service level",
        "value": "Best efforts at 99 per cent monthly availability for the connection method and Flinks Connect, excluding maintenance and bank-side faults, per the Master Terms"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II per the docs and the data safety page, with the report on request. The Master Terms also commit to ISO 27001 audit reports"
      },
      {
        "label": "AI resources",
        "value": "llms.txt, Markdown twins, a skill file at https://docs.flinks.com/skill.md and a documentation MCP server at https://docs.flinks.com/mcp with two read-only tools"
      },
      {
        "label": "SDKs",
        "value": "None found. Mobile apps load Flinks Connect in a WebView"
      }
    ],
    "provenance": {
      "legalEntity": "Flinks Technology Inc.",
      "domain": "flinks.com",
      "domainRegistered": "1997-06-03",
      "endpointOnVendorDomain": false,
      "terms": "https://www.flinks.com/terms-and-conditions",
      "privacy": "https://www.flinks.com/privacy-policy",
      "statusPage": "https://status.flinks.com",
      "changelog": "https://docs.flinks.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms link is the Master Terms and Conditions, last updated 3 August 2023, which govern use of the Flinks technology under an order form and name Flinks Technology Inc. Service schedules for connectivity, enrichment and upload are separate pages on flinks.com.",
        "The privacy link holds the General Privacy Statement (22 September 2022) and the Services Privacy Statement (19 April 2024) on one page. The Services statement covers bank data read through the product and names National Bank of Canada as Flinks' parent company.",
        "API calls go to https://{instance}-api.private.fin.ag and the widget to https://{instance}-iframe.private.fin.ag. Flinks Outbound answers at ob.flinksapp.com. Neither is under flinks.com, so the endpoint is recorded as off the vendor's domain. We did not confirm the registrant of fin.ag.",
        "flinks.com/.well-known/security.txt, www.flinks.com/.well-known/security.txt and docs.flinks.com/.well-known/security.txt return 404. The security page gives security@flinks.com for vulnerability reports.",
        "status.flinks.com runs on incident.io. changelog.flinks.com redirects to docs.flinks.com/changelog.",
        "Verisign RDAP gives 1997-06-03 as the registration date of flinks.com and GoDaddy.com, LLC as registrar. No street address for the company was found on the pages read."
      ],
      "score": 71,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Flinks Technology Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "flinks.com, registered 1997-06-03 (29 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on flinks.com",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.flinks.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.flinks.com/terms-and-conditions",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2023-08-03",
          "words": 9312,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last update: August 3, 2023",
              "says": "Last updated 2023-08-03"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Agreement is governed by, and will be interpreted and enforced in accordance with, the Laws of the province of Ontario and the federal Laws of Canada applicable therein.",
              "says": "The law of the Province of Ontario"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…LAW, EITHER PARTY’S TOTAL LIABILITY TO THE OTHER PARTY UNDER OR ARISING OUT OF THE AGREEMENT WILL BE LIMITED TO THE AGGREGATE AMOUNTS PAID OR DUE AND OWING BY CLIENT TO FLINKS HEREUNDER IN THE TWELVE (12) MONTH PERIOD PRIOR TO THE ORIGINATION OF THE CLAIM ASSERTING LIABILITY.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Either party may terminate the Master Terms or any individual Order Form upon thirty (30) days’ prior written notice to the other party where such other party breaches any of its material obligations hereunder, and such breach is not cured, or is incapable of being cured, within the foregoing thirty (30) day notice pe…"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "By executing an Order Form, Client agrees and recognizes that Flinks may, from time to time and in its’ sole discretion, modify these Master Terms without prior notice to Client.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "EXCEPT FOR FLINKS’ COMMITMENT TO PROVIDE THE SERVICE(S) IN ACCORDANCE WITH THE SERVICE LEVELS, FLINKS MAKES NO WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, REGARDING THE SERVICES, AND FLINKS SPECIFICALLY DISCLAIMS ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOS…"
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "By executing an Order Form, Client agrees and recognizes that Flinks may, from time to time and in its’ sole discretion, modify these Master Terms without prior notice to Client.",
              "costsPoints": true
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last update: August 3, 2023"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The client may not make any statement about Flinks, its systems, the services or a security breach, public or otherwise, without prior written authorisation from Flinks.",
              "quote": "Client shall not make or publish any representation or statement of any kind, whether public or otherwise, concerning Flinks, Flinks’ Systems, the Services (including any Security Breach), or Client’s use thereof, without the prior written authorization of Flinks."
            },
            {
              "date": "2026-10-08",
              "text": "The client must take part in one SOC 2 Type II audit each calendar year.",
              "quote": "Client shall participate in one (1) SOC 2 Type II (or any successor authoritative guidance for reporting on service organizations) audit each calendar year."
            },
            {
              "date": "2026-10-08",
              "text": "On expiry or termination, end-customer data is deleted in the normal course of operations, and Flinks may keep it where required to resolve a dispute or to assert or defend a claim.",
              "quote": "End-Customer Data will be deleted in the normal course of Flinks operations, provided however that Flinks reserves the right to preserve End-Customer Data if required to resolve a dispute or assert or defend any claim."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.flinks.com/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-09-22",
          "words": 13192,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "This General Privacy Statement was last updated on September 22, 2022. From time to time, Flinks may update this General Privacy Statement to reflect changes to Flinks’ services or purposes for which…",
              "says": "Last updated 2022-09-22"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Please read the descriptions below carefully in order to understand which privacy statement applies, and how we collect, use, and share your information:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will store the Information you provide and Information obtained from your financial institution for as long as it is necessary to provide our clients with our services.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "…bank account with one of our clients’ services (e.g., a mobile or web application or financial service provider), and the information Flinks receives as a result of your use of those client services."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Flinks does not sell or obtain any monetary consideration in exchange for the personal information it shares under this Privacy Statement.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Where Flinks has collected Personal Information pursuant to this Privacy Statement, you have the right to access the records Flinks holds containing your Personal Information."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "however, should you have any questions about it, please let us know at privacy@flinks.com.",
              "says": "privacy@flinks.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "This General Privacy Statement was last updated on September 22, 2022. From time to time, Flinks may update this General Privacy Statement to reflect changes to Flinks’ services or purposes for which…"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Flinks lists improving and further developing its existing services among the uses of personal information it receives from end customers and their financial institutions.",
              "quote": "To improve, enhance, modify, add to, and further develop our existing services;"
            },
            {
              "date": "2026-10-08",
              "text": "The service providers that process personal information for Flinks include other data aggregators, used for redundancy during an outage or for access to institutions Flinks cannot reach.",
              "quote": "Other data aggregators who provide similar services to Flinks, who provide redundancies in the event of an outage, or access to financial institutions or data Flinks may not have connectivity with."
            },
            {
              "date": "2026-10-08",
              "text": "Where Flinks suspects an illegal transaction through Flinks Pay, it reports the person and the transaction to FINTRAC, other authorities as required, and its parent company, National Bank of Canada.",
              "quote": "Flinks will report information about you and any associated transaction(s) to the Financial Transactions and Reports Analysis Centre of Canada (“FINTRAC”) and any other law enforcement or regulatory body as required, as well as Flinks’ parent company, National Bank of Canada (“National Bank”)"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/flinks.json",
    "live": {
      "slug": "flinks",
      "vendorStatus": {
        "page": "https://status.flinks.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-09T01:52:03.115000439Z"
      },
      "updatedAt": "2026-10-09T01:52:03.115000439Z"
    }
  }
}
