{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "mx",
    "name": "MX Platform API",
    "vendor": "MX Technologies, Inc.",
    "vendorUrl": "https://www.mx.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "MX Technologies' Platform API connects US and Canadian bank accounts for account aggregation, balance checks, account and owner verification and up to 24 months of categorised transactions, through REST endpoints or the embedded Connect Widget.",
    "url": "https://www.anchorterminal.com/tools/mx",
    "markdownUrl": "https://www.anchorterminal.com/tools/mx.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mx.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mx.json",
    "repo": "https://github.com/mxenabled/openapi",
    "license": "Proprietary service. The SDKs and the OpenAPI files on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.mx.com",
    "packages": [
      {
        "registry": "npm",
        "name": "mx-platform-node"
      },
      {
        "registry": "pypi",
        "name": "mx-platform-python"
      },
      {
        "registry": "npm",
        "name": "@mxenabled/web-widget-sdk"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve for development, MX approval for production. Every request sends Basic auth of `client_id:api_key` from the Client Dashboard, plus `Accept-Version`. Development and production keys are separate, and a rotated key stays valid for 30 days. All calling IP addresses must be allowlisted in the dashboard, and MX reviews addresses outside the US. Mutual TLS is optional. Four processor endpoints take a Bearer token exchanged from an authorisation code. OAuth institutions appear only after MX registers the client with them.",
    "pricing": "paid",
    "pricingNotes": "No public price. www.mx.com/pricing/ returns 404 and the product pages ask for a demo. Developer API keys are free and reach the integration environment (`https://int-api.mx.com`) with up to 100 users and a subset of institutions, so an agent's owner can test without a contract. Production keys are requested from MX in the Client Dashboard (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or mx.com (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 9,
      "npmWeekly": 2631,
      "pypiWeekly": 1997,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.mx.com/",
    "llmsTxt": "https://docs.mx.com/llms.txt",
    "openapi": "https://docs.mx.com/openapi/platform-api/v20260929.yaml",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.identity",
      "bank.consent"
    ],
    "tags": [
      "hosted",
      "openapi",
      "llms-txt",
      "typescript",
      "python",
      "ruby",
      "java",
      "csharp",
      "webhooks",
      "sales-led",
      "enterprise",
      "status-page",
      "soc2"
    ],
    "lastRelease": "2026-09-29",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 62.5,
      "grade": "B",
      "agentReady": false,
      "rank": 336,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 74,
        "maintenance": 71,
        "payments": 15,
        "reliability": 63,
        "schema": 85,
        "security": 60,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 63,
          "points": 12.6,
          "reason": "Graded as a hosted API. status.mx.com lists 15 components, the Platform API among them, with incident history back to February 2025 (20). From 10 July to 8 October 2026 it records elevated errors across MX's traffic on 10 July (critical, about 42 minutes), across products on 1 August (major, about 89 minutes) and on 2 October (major, about 37 minutes), plus a Customer Analytics dashboard fault on 21 August. One ran past an hour and three were platform-wide, so 8 of 30, between the one-major and several-majors bands. Rate limits published per method and environment (15). A 429 has no `Retry-After`, but the docs say limits reset each second and ask for exponential backoff, and a client-set `id` returns 409 on a repeated create (10 of 15). No SLA found (0). The Platform API is generally available at v20260929 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "OpenAPI 3.0 files for v20260929, v20250224 and v20111101 are linked from llms.txt. The current one has 133 paths and 181 operations (25). llms.txt and a Markdown twin of each page (10). Descriptions say what each endpoint does, and the nine deprecated operations name their replacements, with little guidance on when not to call one (15 of 20). Parameters are typed, with 53 enums, but `use_case` is a plain string and `metadata` a free string (10 of 15). The file carries 938 examples but lists only 2xx responses, so error shapes live on the Errors page alone (10 of 15). Dated versions set by `Accept-Version`, an upgrade guide and a dated changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "v20260929 returns core fields by default and adds related data only through `includes[]`, and `records_per_page` runs from 10 to 1,000 on the main lists (20 of 25). Page-number pagination with a `pagination` object, date, created and updated ranges and category filters on transactions, a default window of 120 days and a six-month maximum range (18 of 20). Errors carry `message`, `status` and `type`, 422s add field-level `errors`, and connection problems arrive as documented member statuses (16 of 20). No idempotency key. A client-set `id` returns 409 on a duplicate, and a throttled aggregation returns 202 with no error, which an agent can misread (10 of 20). SDKs for Node, Python, Ruby, Java and C#, none for v20260929, and three headers plus an allowlisted IP on every call (10 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "Basic auth with a `client_id` and `api_key` in a header, never in the URL. Development and production keys are separate, rotation keeps the old key alive for 30 days, every calling IP must be allowlisted, and mutual TLS is optional. No scopes (22 of 30). No read-only key and no confirmation on deletes. `data_request.products` limits what a member aggregates, and deleted members sit soft-deleted for about two weeks (6 of 20). Responses carry bank-written text, and the docs warn that strings can hold characters such as `\u003c` and ask clients to sanitise before display, with nothing on model input (6 of 15). Client Dashboard logs show request and response payloads for seven days in production, with a per-user lookup (11 of 15). Signed security.txt valid to 31 December 2030, SOC 2 Type II and PCI DSS named on the trust page, a public SOC 3 report, no bug bounty found (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 15,
          "points": 1.88,
          "reason": "No x402, MPP or L402 (0). No prices anywhere on mx.com. /pricing/ returns 404 and product pages ask for a demo (0). Developer keys are free and reach the integration environment with up to 100 users. The sign-up form is drawn by script, so we could not confirm that it asks for no card (15 of 20). A person signs up in a browser, verifies an email address, allowlists an IP and asks MX for production keys (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "reason": "v20260929 was released on 29 September 2026 (30). Four dated changelog entries in the last 90 days, on 24 August and 3, 16 and 29 September (20). A dated changelog and a support desk that states a first reply within about 24 business hours. On GitHub, issues on `mx-platform-node`, `mx-platform-java` and `openapi` sit open for months or years with no reply (8 of 15). Five official SDKs, last released 29 January to 18 February 2026, and the public `mxenabled/openapi` repository has no v20260929 file (8 of 15). The Node SDK has generate, test and publish workflows. Dependency pull requests on the Java SDK have been open since 2023 (5 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 46, provenance 80",
          "reason": "Closed service. The only terms on mx.com are an end-user Terms of Use dated 15 January 2020, and the agreement a client signs is not public. SDKs and OpenAPI files are MIT (8 of 30). The privacy statement of 30 September 2025 says it does not cover data MX processes for clients. The trust page says all data is hosted in US data centres, and the API docs say deleted objects are purged after about two weeks. No DPA or retention schedule is public (10 of 30). Written version policy with 18 months of support and 12 of deprecation, plus a deprecations page with dates and RFC 9745 and RFC 8594 headers (20). US-only hosting is stated and Akamai is named for DDoS scrubbing. No sub-processor list found (8 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "v20260929 returns core fields by default and adds related data only through `includes[]`, and `records_per_page` runs from 10 to 1,000 on the main lists (20 of 25). Page-number pagination with a `pagination` object, date, created and updated ranges and category filters on transactions, a default window of 120 days and a six-month maximum range (18 of 20). Errors carry `message`, `status` and `type`, 422s add field-level `errors`, and connection problems arrive as documented member statuses (16 of 20). No idempotency key. A client-set `id` returns 409 on a duplicate, and a throttled aggregation returns 202 with no error, which an agent can misread (10 of 20). SDKs for Node, Python, Ruby, Java and C#, none for v20260929, and three headers plus an allowlisted IP on every call (10 of 15).",
          "maintenance": "v20260929 was released on 29 September 2026 (30). Four dated changelog entries in the last 90 days, on 24 August and 3, 16 and 29 September (20). A dated changelog and a support desk that states a first reply within about 24 business hours. On GitHub, issues on `mx-platform-node`, `mx-platform-java` and `openapi` sit open for months or years with no reply (8 of 15). Five official SDKs, last released 29 January to 18 February 2026, and the public `mxenabled/openapi` repository has no v20260929 file (8 of 15). The Node SDK has generate, test and publish workflows. Dependency pull requests on the Java SDK have been open since 2023 (5 of 10).",
          "payments": "No x402, MPP or L402 (0). No prices anywhere on mx.com. /pricing/ returns 404 and product pages ask for a demo (0). Developer keys are free and reach the integration environment with up to 100 users. The sign-up form is drawn by script, so we could not confirm that it asks for no card (15 of 20). A person signs up in a browser, verifies an email address, allowlists an IP and asks MX for production keys (0).",
          "reliability": "Graded as a hosted API. status.mx.com lists 15 components, the Platform API among them, with incident history back to February 2025 (20). From 10 July to 8 October 2026 it records elevated errors across MX's traffic on 10 July (critical, about 42 minutes), across products on 1 August (major, about 89 minutes) and on 2 October (major, about 37 minutes), plus a Customer Analytics dashboard fault on 21 August. One ran past an hour and three were platform-wide, so 8 of 30, between the one-major and several-majors bands. Rate limits published per method and environment (15). A 429 has no `Retry-After`, but the docs say limits reset each second and ask for exponential backoff, and a client-set `id` returns 409 on a repeated create (10 of 15). No SLA found (0). The Platform API is generally available at v20260929 (10).",
          "schema": "OpenAPI 3.0 files for v20260929, v20250224 and v20111101 are linked from llms.txt. The current one has 133 paths and 181 operations (25). llms.txt and a Markdown twin of each page (10). Descriptions say what each endpoint does, and the nine deprecated operations name their replacements, with little guidance on when not to call one (15 of 20). Parameters are typed, with 53 enums, but `use_case` is a plain string and `metadata` a free string (10 of 15). The file carries 938 examples but lists only 2xx responses, so error shapes live on the Errors page alone (10 of 15). Dated versions set by `Accept-Version`, an upgrade guide and a dated changelog (15).",
          "security": "Basic auth with a `client_id` and `api_key` in a header, never in the URL. Development and production keys are separate, rotation keeps the old key alive for 30 days, every calling IP must be allowlisted, and mutual TLS is optional. No scopes (22 of 30). No read-only key and no confirmation on deletes. `data_request.products` limits what a member aggregates, and deleted members sit soft-deleted for about two weeks (6 of 20). Responses carry bank-written text, and the docs warn that strings can hold characters such as `\u003c` and ask clients to sanitise before display, with nothing on model input (6 of 15). Client Dashboard logs show request and response payloads for seven days in production, with a per-user lookup (11 of 15). Signed security.txt valid to 31 December 2030, SOC 2 Type II and PCI DSS named on the trust page, a public SOC 3 report, no bug bounty found (15 of 20).",
          "transparency": "Closed service. The only terms on mx.com are an end-user Terms of Use dated 15 January 2020, and the agreement a client signs is not public. SDKs and OpenAPI files are MIT (8 of 30). The privacy statement of 30 September 2025 says it does not cover data MX processes for clients. The trust page says all data is hosted in US data centres, and the API docs say deleted objects are purged after about two weeks. No DPA or retention schedule is public (10 of 30). Written version policy with 18 months of support and 12 of deprecation, plus a deprecations page with dates and RFC 9745 and RFC 8594 headers (20). US-only hosting is stated and Akamai is named for DDoS scrubbing. No sub-processor list found (8 of 20)."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://docs.mx.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Platform API introduction, environments and deletion",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/introduction.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication, IP allowlisting, mutual TLS, encrypted responses",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/authentication-and-security.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits and 429 behaviour",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "aggregation throttling and balance check limits",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/aggregation.md",
            "seen": "2026-10-08"
          },
          {
            "what": "errors",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "requests, pagination, identifiers",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/requests-and-responses.md",
            "seen": "2026-10-08"
          },
          {
            "what": "version support policy",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "deprecations and response headers",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/deprecations.md",
            "seen": "2026-10-08"
          },
          {
            "what": "upgrade guide",
            "url": "https://docs.mx.com/api-reference/platform-api/v20260929/overview/upgrade-guide.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI file, v20260929",
            "url": "https://docs.mx.com/openapi/platform-api/v20260929.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.mx.com/resources/changelog/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API keys and rotation",
            "url": "https://docs.mx.com/resources/client-dashboard/manage-api-keys.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Client Dashboard, logs and IP allowlist",
            "url": "https://docs.mx.com/resources/client-dashboard/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MX Bank test institution",
            "url": "https://docs.mx.com/resources/test-platform/mxbank/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "support hours and response times",
            "url": "https://docs.mx.com/support.md",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://status.mx.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.mx.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "developer sign-up page",
            "url": "https://dashboard.mx.com/sign_up",
            "seen": "2026-10-08"
          },
          {
            "what": "trust page",
            "url": "https://www.mx.com/trust/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.mx.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy statement",
            "url": "https://www.mx.com/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use (end users)",
            "url": "https://www.mx.com/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing URL, 404",
            "url": "https://www.mx.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK repository and tags",
            "url": "https://github.com/mxenabled/mx-platform-node",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK repository and tags",
            "url": "https://github.com/mxenabled/mx-platform-python",
            "seen": "2026-10-08"
          },
          {
            "what": "public OpenAPI repository",
            "url": "https://github.com/mxenabled/openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry",
            "url": "https://registry.npmjs.org/mx-platform-node",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/mx.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether the Client Dashboard sign-up asks for a card. The form is drawn by script and the page says only that developer accounts are free",
          "unchecked: the agreement a client accepts at sign-up or signs for production. No developer or service agreement is linked from mx.com, the docs or the sign-up page we could read",
          "unchecked: MX's SOC 2 report, DPA and sub-processor list, which the trust page places behind an NDA request on UpGuard",
          "No SLA, price or bug bounty was found in the pages read",
          "The status page was moved to a new host around 30 July 2026 and older incidents were imported on 4 August, so their impact labels are as imported",
          "Country coverage beyond the US and Canada was not established. mx.com names those two"
        ]
      },
      "negative": 0,
      "verdict": "Three public OpenAPI files, llms.txt, Markdown docs and a written version policy with 18 months of support and `Deprecation` and `Sunset` response headers. No price, client agreement or SLA is published, production keys need MX's approval, every calling IP address must be allowlisted, and the status page records three platform-wide error incidents since 10 July 2026.",
      "bestFor": "A US or Canadian bank, credit union or fintech with a signed MX contract that wants aggregation, verification and categorised transactions plus embeddable finance widgets.",
      "strengths": [
        "OpenAPI files for all three Platform API versions, an llms.txt index and a Markdown twin of every docs page",
        "Each version is supported for at least 18 months, then deprecated for 12, and deprecated endpoints send `Deprecation`, `Sunset` and `Link` headers",
        "Rate limits are published per method, 2,000 GET and 750 POST requests a second in production",
        "Free developer keys reach the integration environment with up to 100 users and the `mxbank` test institution",
        "API keys rotate with a 30-day overlap, every calling IP must be allowlisted, and mutual TLS and JWE-encrypted responses are available"
      ],
      "weaknesses": [
        "No public price, SLA or client agreement. Production keys are requested from MX in the Client Dashboard",
        "Three platform-wide incidents of elevated errors since 10 July 2026 (42, 89 and 37 minutes), marked critical or major",
        "One `client_id` and `api_key` pair reaches every endpoint, with no scopes and no read-only key",
        "No SDK targets v20260929. The newest SDK releases date from January and February 2026 and cover v20250224 and v20111101",
        "A 429 carries no `Retry-After`, and the API has no idempotency key",
        "The privacy statement excludes data MX processes for clients, and no DPA or sub-processor list is public"
      ],
      "agentNotes": [
        "Send `Accept: application/json`, `Accept-Version: v20260929` and Basic auth of `client_id:api_key` on every call. A missing version returns 406",
        "Ask the owner to allowlist the calling machine's static IP in the Client Dashboard first. Other addresses get 403, and some failed authentication returns 404",
        "Test against `https://int-api.mx.com` with institution `mxbank`, username `mxuser` and any password. It has no aggregation throttle",
        "Set your own `id` when creating users and members. A repeat returns 409, which makes a retried create safe",
        "Expect 202 without an error when a standard aggregation is throttled (three hours by default). Balance checks stop at 5 per member every 2 hours with 429",
        "Pass `includes[]=merchant` or `includes[]=category` as an array on transaction lists. A comma-separated string returns 400"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 62.5
        }
      ],
      "editorialScores": {
        "ergonomics": 74,
        "maintenance": 71,
        "payments": 15,
        "reliability": 63,
        "schema": 85,
        "security": 60,
        "transparency": 46
      },
      "provenanceScore": 80
    },
    "connect": {
      "install": "npm install mx-platform-node@^3",
      "http": "curl -X GET 'https://int-api.mx.com/users' \\\n  -H 'Accept: application/json' \\\n  -H 'Accept-Version: v20260929' \\\n  -H 'Authorization: Basic BASE_64_ENCODING_OF{client_id:api_key}'"
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/mx"
    },
    "notable": [
      "Version v20260929 was released on 29 September 2026 with breaking changes. Responses return core fields by default and related data only through `includes[]` (https://docs.mx.com/api-reference/platform-api/v20260929/overview/upgrade-guide.md)",
      "Each version is supported for at least 18 months and deprecated for 12 before removal. Deprecated endpoints send `Deprecation`, `Sunset` and `Link` headers, then 410 (https://docs.mx.com/api-reference/platform-api/v20260929/overview/deprecations.md)",
      "Accounts can be connected without the Connect Widget. Read `/institutions/{institution_code}/credentials`, then POST the member with the user's credentials (https://docs.mx.com/products/connectivity/overview/connectivity-integration-guides/api-only-flow.md)",
      "MX aggregates each member in the background about every 24 hours. A standard aggregation started by the client is throttled to one per three hours and answers 202 when throttled (https://docs.mx.com/api-reference/platform-api/v20260929/overview/aggregation.md)",
      "All requests must come from an allowlisted static IP, in every environment. Ranges from /22 to /32 are accepted and approval can take several days (https://docs.mx.com/resources/client-dashboard/index.md)",
      "status.mx.com records elevated errors across the platform on 10 July, 1 August and 2 October 2026, lasting about 42, 89 and 37 minutes (https://status.mx.com/api/v2/incidents.json)",
      "No MCP server was found in MX's docs or under an MX namespace in the official MCP registry (https://registry.modelcontextprotocol.io/v0.1/servers?search=mx)",
      "The Node SDK publishes one major version per API version, 2.x for v20111101 and 3.x for v20250224, with none yet for v20260929 (https://github.com/mxenabled/mx-platform-node)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Environments",
        "value": "Integration at https://int-api.mx.com (free, up to 100 users, a subset of institutions) and production at https://api.mx.com"
      },
      {
        "label": "Versions",
        "value": "v20260929 (current, 29 September 2026), v20250224 and v20111101, chosen with the `Accept-Version` header. A missing version returns 406"
      },
      {
        "label": "Products",
        "value": "Account aggregation, balance checks, instant account verification, account owner identification, extended transaction history (up to 24 months), statements, microdeposits, investment holdings, processor tokens"
      },
      {
        "label": "Countries",
        "value": "US and Canada, per mx.com"
      },
      {
        "label": "Rate limits",
        "value": "Production 2,000 GET, 750 POST, 750 PUT and 150 DELETE a second per client. Integration 300, 100, 100 and 50. Balance checks 5 per member every 2 hours"
      },
      {
        "label": "Test data",
        "value": "Institution `mxbank` with username `mxuser` and passwords that set the connection status, plus MXCU test institutions for OAuth"
      },
      {
        "label": "Consent and revocation",
        "value": "Connect Widget or API-created members. Deleting a member removes its accounts and transactions, soft-deleted first and purged after about two weeks"
      },
      {
        "label": "Pagination",
        "value": "`page` and `records_per_page` (default 25, 10 to 1,000 on main lists), with a `pagination` object in each list response"
      },
      {
        "label": "Errors",
        "value": "JSON `error` object with `message`, `status` and `type`, field-level `errors` on some 422s. 429 without `Retry-After`"
      },
      {
        "label": "SDKs",
        "value": "Node `mx-platform-node` 2.1.0 and 3.0.0, Python `mx-platform-python` 1.12.0, Ruby, Java and C#, all generated from OpenAPI, MIT. Web and React Native widget SDKs"
      },
      {
        "label": "Logs",
        "value": "Client Dashboard logs with request and response payloads for 7 days in production, and a user lookup of connection attempts"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II and PCI DSS per mx.com/trust, with a public SOC 3 report. Other documents through UpGuard under NDA"
      },
      {
        "label": "Support",
        "value": "support.mx.com, Monday to Friday 9 to 5 Mountain Time, first reply in about 24 business hours, 30 days' notice of maintenance"
      }
    ],
    "provenance": {
      "legalEntity": "MX Technologies, Inc.",
      "domain": "mx.com",
      "domainRegistered": "1994-04-28",
      "endpointOnVendorDomain": true,
      "terms": "",
      "privacy": "",
      "statusPage": "https://status.mx.com",
      "changelog": "https://docs.mx.com/resources/changelog/",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The privacy statement and the terms name MX Technologies, Inc., 3401 North Thanksgiving Way, Suite 500, Lehi, Utah 84043.",
        "`terms` is left out. The only terms on mx.com are an end-user and website Terms of Use dated 15 January 2020 (https://www.mx.com/terms/). No client or developer agreement for the Platform API is published.",
        "`privacy` is left out. The privacy statement at https://www.mx.com/privacy/ (30 September 2025) says it does not apply to personal data MX processes as a processor on behalf of its clients, which is the data the API handles.",
        "The API answers at api.mx.com and int-api.mx.com.",
        "security.txt at https://www.mx.com/.well-known/security.txt is PGP-signed, gives vulns@mx.com and expires 2030-12-31. Its Policy link redirects to the trust page.",
        "Verisign's RDAP server gives a registration date of 1994-04-28 and GoDaddy.com, LLC as registrar."
      ],
      "score": 80,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "MX Technologies, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "mx.com, registered 1994-04-28 (32 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.mx.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Privacy policy",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Status page",
          "value": "status.mx.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/mx.json",
    "live": {
      "slug": "mx",
      "probe": {
        "target": "https://api.mx.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:16.259214321Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 675,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 726,
        "p95ms24h": 827,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.mx.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:06:13.020289952Z"
      },
      "updatedAt": "2026-10-08T21:12:16.259214321Z"
    }
  }
}
