{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "tink",
    "name": "Tink",
    "vendor": "Tink AB (Visa)",
    "vendorUrl": "https://tink.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "Tink is a European open banking platform owned by Visa. Its REST API and hosted Tink Link flow read accounts, balances and transactions with the account holder's consent, and start bank payments.",
    "url": "https://www.anchorterminal.com/tools/tink",
    "markdownUrl": "https://www.anchorterminal.com/tools/tink.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tink.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tink.json",
    "repo": "https://github.com/tink-ab/tink-link-ios",
    "license": "Proprietary service under Tink's Master Service Agreement. The Tink Link SDKs for iOS and Android on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.tink.com",
    "packages": [],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 with a `client_id` and `client_secret` from the Tink Console, sent in the POST body to https://api.tink.com/api/v1/oauth/token. A client token lasts 30 minutes and carries only the scopes requested. Data calls need a user token, valid two hours, obtained through an authorisation grant for a Tink user or from the code Tink Link returns after bank consent. Mutual TLS is accepted as an alternative client authentication method. Console signup is self-serve for the sandbox. Live access is by sales contract, with customer due diligence when Tink's own licence is used.",
    "pricing": "paid",
    "pricingNotes": "No public prices. The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and says listed prices apply only to existing customers (https://tink.com/pricing/, checked 2026-10-08). The FAQ says there is no pay-per-use option and that a free Console account gives test data in a sandbox (https://tink.com/faq/). No card is mentioned for signup. Fees are set in an order form and billed monthly in arrears under the MSA.",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the API reference introduction or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.tink.com",
    "llmsTxt": "https://docs.tink.com/llms.txt",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.consent",
      "bank.payments",
      "bank.identity"
    ],
    "tags": [
      "hosted",
      "oauth",
      "llms-txt",
      "webhooks",
      "sandbox",
      "eu",
      "uk",
      "enterprise",
      "sales-led",
      "status-page",
      "closed-source"
    ],
    "lastRelease": "2026-09-15",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 62.5,
      "grade": "B",
      "agentReady": false,
      "rank": 337,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 74,
        "maintenance": 69,
        "payments": 10,
        "reliability": 62,
        "schema": 73,
        "security": 63,
        "transparency": 90
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 62,
          "points": 12.4,
          "reason": "Graded with the hosted lines. Statuspage at status.tink.com with 14 product components and incident history (20). In the 90 days to 8 October the feed lists one critical incident, on 16 July 2026, when authentication, consent, account data and payment flows failed in all European markets from 09:54 to 10:56 CEST, with a post-mortem published on 22 July. It also lists a 43-minute Payment Initiation incident on 25 September and 503 responses from Data Enrichment for 81 minutes on 6 October (10 of 30). Rate limits are stated as per app ID with no numbers (3 of 15). The reference documents the 429 status and an Idempotency-Key header with 24-hour keys, and tells customers to contact support on 429. No Retry-After or backoff guidance was found (9 of 15). Published SLAs of 99.7 per cent monthly uptime, a target under Basic Support and a commitment under service levels 1 to 3 (10). The v1 API and the Data v2 accounts and transactions endpoints carry no BETA tag (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 73,
          "points": 11.86,
          "reason": "The API reference holds Swagger definitions for 205 operations, but only inside the docs app's JavaScript bundle. No downloadable spec was found, and Postman collections are published per product (10 of 25). llms.txt lists about 280 guides, each with a Markdown twin. The API reference is not in it (10). 191 of 205 operations have a description and the guides explain when to pick one-time or continuous access (14 of 20). Parameters are typed, 20 carry enums, and several older v1 endpoints take whole request bodies by reference (11 of 15). Guides carry curl requests and JSON responses, and each product has an error page with status and reason tables (13 of 15). The version sits in the path (v1, some v2) and the changelog has 367 dated entries (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "Transactions return at most 100 a page and take date, account and status filters. No field selection was found (18 of 25). `pageSize` and `pageToken` on 20 operations, with snake-case equivalents on 6 more (18 of 20). Error pages list statuses and reasons with a `tracking_id`, and provider consent errors carry a `retryable` flag. API errors on Data v2 return a generic error object (16 of 20). Idempotency-Key is documented with 24-hour keys and appears on 7 write operations. Reads are safe to repeat (16 of 20). A first data call takes four token and user calls plus a browser consent, and the only SDKs found are Tink Link for iOS and Android (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 63,
          "points": 11.03,
          "reason": "OAuth 2.0 client credentials sent in the POST body, scopes named per endpoint, 30-minute client tokens, two-hour user tokens and mutual TLS as an alternative. Secret rotation was not confirmed (27 of 30). Read scopes are separate from write and payment scopes, the account holder consents per bank in Tink Link, and one-time access data is deleted after 24 hours (15 of 20). Responses include bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Every response returns an X-Request-ID and the Console has analytics. No operator audit log was found in the docs (4 of 15). The Privacy and Security Documentation describes controls aligned with ISO/IEC 27002, annual independent audits and penetration tests, and security.txt points to Visa's disclosure policy. No named certificate, bug bounty or security contact was found on the pages read (10 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and the FAQ says there is no pay-per-use option (0). A free, self-serve Console account with sandbox test data and no card mentioned. No free live tier (10 of 20). A person signs up in the Console (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 69,
          "points": 6.04,
          "reason": "The newest changelog entry is 15 September 2026, 23 days before the check (30). Three dated entries in the last 90 days, on 4 August, 7 September and 15 September (20). Closed service with an active changelog and support through the Visa Support Hub. Basic Support carries no guaranteed response time, and GitHub issue replies were not sampled (8 of 15). Tink Link for iOS 5.1.0 shipped on 6 May 2026. The Android SDK's newest tag is 3.0.1 from 13 March 2025, with commits to 15 July 2026, and no server-side SDK was found (8 of 15). Neither SDK repository has a public CI workflow (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 90,
          "points": 7.88,
          "note": "editorial 79, provenance 100",
          "reason": "Closed service with a public Master Service Agreement dated 9 December 2025, governed by Swedish law. The mobile SDKs are MIT (15 of 30). A public DPA, a Privacy and Security Documentation and an end-user privacy notice agree on handling. Customer data is deleted within 30 days of termination and one-time access data after 24 hours. The end-user notice gives no fixed retention periods (24 of 30). The MSA commits to reasonable efforts at 90 days' notice before a product is discontinued, and the changelog carries dated deprecations, such as TLS 1.2 ending on 31 December 2027, announced on 31 March 2026 (17 of 20). The sub-processor list of 1 October 2025 names AWS and Google Cloud with EEA processing, and the MSA sets the data region as the EU, EEA and UK (18 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Tink AB is authorised by the Swedish FSA under 44059 and Tink Financial Services Limited by the FCA under 988456 (+5)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Transactions return at most 100 a page and take date, account and status filters. No field selection was found (18 of 25). `pageSize` and `pageToken` on 20 operations, with snake-case equivalents on 6 more (18 of 20). Error pages list statuses and reasons with a `tracking_id`, and provider consent errors carry a `retryable` flag. API errors on Data v2 return a generic error object (16 of 20). Idempotency-Key is documented with 24-hour keys and appears on 7 write operations. Reads are safe to repeat (16 of 20). A first data call takes four token and user calls plus a browser consent, and the only SDKs found are Tink Link for iOS and Android (6 of 15).",
          "maintenance": "The newest changelog entry is 15 September 2026, 23 days before the check (30). Three dated entries in the last 90 days, on 4 August, 7 September and 15 September (20). Closed service with an active changelog and support through the Visa Support Hub. Basic Support carries no guaranteed response time, and GitHub issue replies were not sampled (8 of 15). Tink Link for iOS 5.1.0 shipped on 6 May 2026. The Android SDK's newest tag is 3.0.1 from 13 March 2025, with commits to 15 July 2026, and no server-side SDK was found (8 of 15). Neither SDK repository has a public CI workflow (3 of 10).",
          "payments": "No x402, MPP or L402 (0). The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and the FAQ says there is no pay-per-use option (0). A free, self-serve Console account with sandbox test data and no card mentioned. No free live tier (10 of 20). A person signs up in the Console (0).",
          "reliability": "Graded with the hosted lines. Statuspage at status.tink.com with 14 product components and incident history (20). In the 90 days to 8 October the feed lists one critical incident, on 16 July 2026, when authentication, consent, account data and payment flows failed in all European markets from 09:54 to 10:56 CEST, with a post-mortem published on 22 July. It also lists a 43-minute Payment Initiation incident on 25 September and 503 responses from Data Enrichment for 81 minutes on 6 October (10 of 30). Rate limits are stated as per app ID with no numbers (3 of 15). The reference documents the 429 status and an Idempotency-Key header with 24-hour keys, and tells customers to contact support on 429. No Retry-After or backoff guidance was found (9 of 15). Published SLAs of 99.7 per cent monthly uptime, a target under Basic Support and a commitment under service levels 1 to 3 (10). The v1 API and the Data v2 accounts and transactions endpoints carry no BETA tag (10).",
          "schema": "The API reference holds Swagger definitions for 205 operations, but only inside the docs app's JavaScript bundle. No downloadable spec was found, and Postman collections are published per product (10 of 25). llms.txt lists about 280 guides, each with a Markdown twin. The API reference is not in it (10). 191 of 205 operations have a description and the guides explain when to pick one-time or continuous access (14 of 20). Parameters are typed, 20 carry enums, and several older v1 endpoints take whole request bodies by reference (11 of 15). Guides carry curl requests and JSON responses, and each product has an error page with status and reason tables (13 of 15). The version sits in the path (v1, some v2) and the changelog has 367 dated entries (15).",
          "security": "OAuth 2.0 client credentials sent in the POST body, scopes named per endpoint, 30-minute client tokens, two-hour user tokens and mutual TLS as an alternative. Secret rotation was not confirmed (27 of 30). Read scopes are separate from write and payment scopes, the account holder consents per bank in Tink Link, and one-time access data is deleted after 24 hours (15 of 20). Responses include bank-written transaction descriptions, and no guidance on treating them as untrusted was found (7 of 15). Every response returns an X-Request-ID and the Console has analytics. No operator audit log was found in the docs (4 of 15). The Privacy and Security Documentation describes controls aligned with ISO/IEC 27002, annual independent audits and penetration tests, and security.txt points to Visa's disclosure policy. No named certificate, bug bounty or security contact was found on the pages read (10 of 20).",
          "transparency": "Closed service with a public Master Service Agreement dated 9 December 2025, governed by Swedish law. The mobile SDKs are MIT (15 of 30). A public DPA, a Privacy and Security Documentation and an end-user privacy notice agree on handling. Customer data is deleted within 30 days of termination and one-time access data after 24 hours. The end-user notice gives no fixed retention periods (24 of 30). The MSA commits to reasonable efforts at 90 days' notice before a product is discontinued, and the changelog carries dated deprecations, such as TLS 1.2 ending on 31 December 2027, announced on 31 March 2026 (17 of 20). The sub-processor list of 1 October 2025 names AWS and Google Cloud with EEA processing, and the MSA sets the data region as the EU, EEA and UK (18 of 20). Regulatory standing counts here as an addition to the checklist (+5 for a named regulator with a register number, +3 for a named regulator alone). Tink AB is authorised by the Swedish FSA under 44059 and Tink Financial Services Limited by the FCA under 988456 (+5)."
        },
        "sources": [
          {
            "what": "status incidents feed",
            "url": "https://status.tink.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.tink.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference (introduction, rate limits, idempotency and Swagger definitions, read from the page's bundle)",
            "url": "https://docs.tink.com/api",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog (entries read from the page's content feed)",
            "url": "https://docs.tink.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "access token guide",
            "url": "https://docs.tink.com/resources/api-setup/get-access-token.md",
            "seen": "2026-10-08"
          },
          {
            "what": "list transactions guide",
            "url": "https://docs.tink.com/resources/transactions/list-transactions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "managing consents guide",
            "url": "https://docs.tink.com/resources/transactions/managing-consents.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Transactions errors",
            "url": "https://docs.tink.com/resources/transactions/handle-transactions-error-codes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Demo Bank guide",
            "url": "https://docs.tink.com/resources/console/demo-bank.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://tink.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ (pricing, sandbox, coverage)",
            "url": "https://tink.com/faq/",
            "seen": "2026-10-08"
          },
          {
            "what": "agreements index (MSA, SLAs, DPA, security and subcontractor documents)",
            "url": "https://tink.com/legal/agreements/",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Service Agreement",
            "url": "https://assets.ctfassets.net/c78bhj3obgck/4rs258WTPok62q9qrmFE1o/b68d1bcc13b5c118503ecffc8647a7d8/Tink_Master_Service_Agreement_2025-12-09.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy and Security Documentation",
            "url": "https://assets.ctfassets.net/c78bhj3obgck/32TNsqcaoHBJCeRx9HDaeQ/585d61e3f8a814c9b11610a9844acdd2/Tink_Privacy_and_Security_Documentation_2025-10-01.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "Subcontractor Documentation",
            "url": "https://assets.ctfassets.net/c78bhj3obgck/2CyMxqrenrxFir1yg0lgcq/342a286880e53ac2b6999f3910638569/Tink_Subcontractor_Documentation_2025-10-01.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA, Basic Support",
            "url": "https://assets.ctfassets.net/c78bhj3obgck/7dcLwRT3DICqAk03JBvET1/f264d736833ef0889b179473a34eca55/SLA_-_Basic_Support_-_2025-10-01.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "legal FAQ (licences and register numbers)",
            "url": "https://tink.com/legal/faq/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://tink.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Tink Link iOS repository (tags and licence)",
            "url": "https://github.com/tink-ab/tink-link-ios",
            "seen": "2026-10-08"
          },
          {
            "what": "Tink Link Android repository (tags and licence)",
            "url": "https://github.com/tink-ab/tink-link-android",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The changelog entry dated 7 September 2026 says redirect requests whose App URI doesn't match a registered Redirect URL are rejected from that same day. Whether customers had earlier notice was not established, so no deduction was made",
          "unchecked: the Console itself (signup steps, whether a card is asked for, secret rotation, any audit log), which sits behind a login",
          "unchecked: GitHub stars and issue responsiveness on the SDK repositories (the GitHub API refused us for rate limits)",
          "unchecked: whether Tink holds a named certificate such as ISO 27001 or SOC 2. None was found on the pages read",
          "unchecked: Visa's vulnerability disclosure page, which security.txt points to",
          "The home page title says 6000 connections while the FAQ says 3,000+ in 18 countries and a docs page says 3,400+",
          "The US product has separate docs at docs.us.tink.com, which were not read. This listing covers the European platform"
        ]
      },
      "negative": 0,
      "verdict": "OAuth client credentials with per-endpoint scopes, token-paged data endpoints and a published MSA, DPA, SLA and sub-processor list. No price is public, live access needs a sales contract, and the API reference has no downloadable spec or published rate-limit numbers.",
      "bestFor": "A company with a contract that needs account, balance and transaction data or bank payments across European markets under Tink's own licences.",
      "strengths": [
        "OAuth 2.0 client credentials with named scopes per endpoint, 30-minute client tokens and two-hour user tokens",
        "Master Service Agreement, DPA, four SLA documents and a sub-processor list with processing locations are public PDFs",
        "Data v2 list endpoints page with `pageSize` and `pageToken`, with date, account and status filters on transactions",
        "Changelog with 367 dated entries, three of them in the 90 days to 8 October 2026",
        "Free Console account with a Demo Bank covering test users in 18 countries"
      ],
      "weaknesses": [
        "No public prices. The pricing page lists Standard as Contact us and Enterprise as Custom pricing, and the FAQ says there is no pay-per-use option",
        "The API reference is a JavaScript app with the Swagger definitions inside its bundle. No downloadable spec was found",
        "Rate limits are per app with no published numbers, and a 429 carries no documented Retry-After",
        "A critical incident on 16 July 2026 stopped authentication, consent, account data and payment flows in all European markets for 62 minutes",
        "security.txt has a Policy line pointing to Visa's disclosure page and no Contact or Expires field"
      ],
      "agentNotes": [
        "Request a client token at https://api.tink.com/api/v1/oauth/token, create a user, request an authorisation grant for that user, then exchange the code for a user token.",
        "Renew tokens on a timer. Client tokens last 30 minutes and user tokens two hours, and the client credentials flow returns no refresh token.",
        "Send the account holder through Tink Link in a browser. Bank consent cannot be completed by API calls alone.",
        "Read transactions from /data/v2/transactions with `pageSize` up to 100 and follow `nextPageToken`.",
        "Send an Idempotency-Key header on consent and payment writes. Keys are kept for 24 hours."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 62.5
        }
      ],
      "editorialScores": {
        "ergonomics": 74,
        "maintenance": 69,
        "payments": 10,
        "reliability": 62,
        "schema": 73,
        "security": 63,
        "transparency": 79
      },
      "provenanceScore": 100
    },
    "connect": {
      "http": "curl -X POST https://api.tink.com/api/v1/oauth/token \\\n  -d \"client_id=$TINK_CLIENT_ID\" \\\n  -d \"client_secret=$TINK_CLIENT_SECRET\" \\\n  -d \"grant_type=client_credentials\" \\\n  -d \"scope=authorization:grant,user:create\""
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/tink"
    },
    "notable": [
      "The docs index at llms.txt lists about 280 guides in 21 sections, each with a Markdown twin at the same path ending in .md. The API reference is not in it (https://docs.tink.com/llms.txt)",
      "The API reference at docs.tink.com/api is a JavaScript app. The Swagger definitions inside its bundle cover 205 operations on 201 paths, of which 61 are tagged ENTERPRISE, 33 BETA and 31 REGION.US (https://docs.tink.com/api)",
      "One-time access keeps a Tink user's data for 24 hours and then deletes it. Continuous access fetches for 90 days, the maximum consent time, before the user must renew (https://docs.tink.com/resources/transactions/introduction-to-transactions.md)",
      "Deleting a credentials object removes the consent, and deleting the last consent for an account permanently deletes its accounts and transactions (https://docs.tink.com/resources/transactions/managing-consents.md)",
      "Demo Bank test users live in the Console per product and market, with test providers such as uk-demobank-open-banking-redirect in 18 countries (https://docs.tink.com/resources/console/demo-bank.md)",
      "The Basic Support SLA, which applies unless a customer buys a higher level, says Tink strives for 99.7 per cent monthly uptime and reports incidents on status.tink.com (https://tink.com/legal/agreements/)",
      "The changelog entry of 31 March 2026 deprecates TLS 1.2, with end of life on 31 December 2027 (https://docs.tink.com/changelog)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.tink.com, paths under /api/v1, /data/v2, /connectivity/v2, /payment and /events/v2. 205 operations in the reference, 87 of them without an ENTERPRISE, BETA or REGION.US tag"
      },
      {
        "label": "Data endpoints",
        "value": "GET /data/v2/accounts, /data/v2/accounts/{id}/balances (BETA), /data/v2/transactions, /data/v2/identities (BETA), plus investment and loan accounts"
      },
      {
        "label": "Consent",
        "value": "The account holder consents in Tink Link at link.tink.com. One-time access data is deleted after 24 hours. Continuous access lasts up to 90 days. GET /api/v1/provider-consents lists consents and DELETE /api/v1/credentials/{id} removes one"
      },
      {
        "label": "Tokens",
        "value": "Client token 30 minutes, user token two hours, scopes named per endpoint such as `accounts:read` and `transactions:read`"
      },
      {
        "label": "Pagination",
        "value": "`pageSize` and `pageToken` on 20 operations, at most 100 transactions a page, with `bookedDateGte`, `bookedDateLte`, `accountIdIn` and `statusIn` filters"
      },
      {
        "label": "Rate limits",
        "value": "Checked per app ID. HTTP 429 when exceeded. No numbers published"
      },
      {
        "label": "Idempotency",
        "value": "Idempotency-Key header, keys kept 24 hours, listed on 7 write operations (consents, mandates, mandate payments, payouts)"
      },
      {
        "label": "Sandbox",
        "value": "Free Console account, sandbox app and Demo Bank test users in 18 countries"
      },
      {
        "label": "Coverage",
        "value": "Tink's FAQ says 3,000+ bank connections in 18 countries. The home page title says 6000 connections"
      },
      {
        "label": "Webhooks",
        "value": "Events v2 webhooks signed with HMAC-SHA256 in an X-Tink-Signature header"
      },
      {
        "label": "SLA",
        "value": "Basic Support 99.7 per cent monthly uptime as a target. Service levels 1 to 3 commit to 99.7 per cent and add response and resolution times"
      },
      {
        "label": "Sub-processors",
        "value": "Amazon Web Services EMEA Sarl and Google Cloud EMEA Limited, both processing in the EEA, plus Tink Germany GmbH and Tink Financial Services Ltd (list dated 1 October 2025)"
      },
      {
        "label": "SDKs",
        "value": "Tink Link for iOS 5.1.0 (6 May 2026) and Android 3.0.1 (13 March 2025), both MIT. No server-side SDK found"
      }
    ],
    "provenance": {
      "legalEntity": "Tink AB",
      "domain": "tink.com",
      "domainRegistered": "1993-03-18",
      "endpointOnVendorDomain": true,
      "terms": "https://assets.ctfassets.net/c78bhj3obgck/4rs258WTPok62q9qrmFE1o/b68d1bcc13b5c118503ecffc8647a7d8/Tink_Master_Service_Agreement_2025-12-09.pdf",
      "privacy": "https://cdn.tink.se/legal/privacy-policy/en_UK/privacy-policy-en_UK-2601.pdf",
      "statusPage": "https://status.tink.com",
      "changelog": "https://docs.tink.com/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Master Service Agreement (version 2025-12-09) names Tink AB, corporate registration number 556898-2192, Regeringsgatan 38, 111 56 Stockholm, and is governed by Swedish law. The legal FAQ says all customer use is governed by it.",
        "The legal FAQ lists Tink AB as a payment institution under the Swedish Financial Supervisory Authority (SFSA ID 44059), Tink Germany GmbH under BaFin (10152149) and Tink Financial Services Limited under the UK FCA (FRN 988456). Tink is a Visa company.",
        "The privacy link is the Visa Open Banking Privacy Notice for End-Users, effective 8 January 2026, which covers the bank data read through the product. A separate General Privacy Notice (effective 8 April 2025) covers website visitors and business contacts, and customer data is governed by the DPA of 1 October 2025.",
        "tink.com/.well-known/security.txt has a Canonical line and a Policy line pointing to Visa's vulnerability disclosure page, with no Contact or Expires field, both of which RFC 9116 requires. It is recorded as valid because the file is served, as with other listings whose file lacks Expires.",
        "The API answers at api.tink.com and Tink Link at link.tink.com. Legal PDFs are served from assets.ctfassets.net and cdn.tink.se.",
        "The changelog at docs.tink.com/changelog renders in JavaScript. We read its entries from the content feed the page itself requests. Verisign RDAP gives the domain registration date and MarkMonitor as registrar."
      ],
      "score": 100,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Tink AB",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "tink.com, registered 1993-03-18 (33 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.tink.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.tink.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/tink.json",
    "live": {
      "slug": "tink",
      "probe": {
        "target": "https://api.tink.com",
        "method": "get",
        "lastAt": "2026-10-08T19:53:04.130514218Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 61,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 54,
        "p95ms24h": 116,
        "samples24h": 27,
        "samples30d": 27,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 27,
            "ok": 27
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.tink.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:51:05.556142173Z"
      },
      "pages": [
        {
          "url": "https://docs.tink.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:19:36.318263547Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "e3b0c44298fc"
        },
        {
          "url": "https://tink.com/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:25:14.991772397Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "b875e338cc34"
        }
      ],
      "updatedAt": "2026-10-08T19:53:04.130514218Z"
    }
  }
}
