{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "yodlee-financial-data",
    "name": "Yodlee Core API",
    "vendor": "Yodlee, Inc.",
    "vendorUrl": "https://www.yodlee.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "Yodlee's Core API (v1.1) aggregates a consumer's bank, card, investment, loan and insurance accounts for balances, categorised transactions, holdings, statements and account-owner details. Consumers link accounts through the embedded FastLink 4 widget.",
    "url": "https://www.anchorterminal.com/tools/yodlee-financial-data",
    "markdownUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/yodlee-financial-data.json",
    "repo": "https://github.com/Yodlee/OpenAPI",
    "license": "Proprietary service. The Swagger file on GitHub is MIT",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "oauth",
    "authNotes": "Self-serve for the sandbox. Registering on the developer portal gives a `clientId`, a `secret` and an admin `loginName` on the API dashboard. `POST /auth/token` takes the id and secret in a form body and a `loginName` header, and returns a bearer token that lasts 30 minutes and acts for that user, or for the admin on administrative calls. Every call also sends `Api-Version: 1.1`. Each environment (sandbox, development, production) has its own credentials. How production access is granted is not stated in the public docs. Full account numbers and holder details need Yodlee Security Office approval.",
    "pricing": "paid",
    "pricingNotes": "No public price. `/pricing` returns 404 on yodlee.com and on the developer portal, and product pages ask for a demo. The sandbox is free on registration, with five preconfigured users and sample data only, so an agent's owner can test without a contract (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the Swagger file or yodlee.com (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 17,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs",
    "openapi": "https://raw.githubusercontent.com/Yodlee/OpenAPI/main/swagger.yaml",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.identity",
      "bank.consent"
    ],
    "tags": [
      "hosted",
      "oauth",
      "openapi",
      "sandbox",
      "webhooks",
      "sales-led",
      "closed-source",
      "enterprise",
      "soc2"
    ],
    "lastRelease": "2026-07-31",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 41.9,
      "grade": "E",
      "agentReady": false,
      "rank": 796,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 12,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 58,
        "maintenance": 33,
        "payments": 15,
        "reliability": 15,
        "schema": 71,
        "security": 49,
        "transparency": 53
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 15,
          "points": 3,
          "reason": "Graded as a hosted API. No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer (0). With no incident history to read, 5 of 30. No rate limit with numbers was found in the docs or the Swagger file, which lists no 429 response (0). No 429, backoff or idempotency guidance found (0). No public SLA. The Security FAQ mentions only contracted recovery targets for clients' disaster recovery options (0). The Core API v1.1 is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "A public Swagger 2.0 file (`Yodlee/OpenAPI`, MIT) with 70 paths, 98 operations and 267 definitions. Its last update, on 22 April 2026, brought it to the November 2025 release, so fields from the June and July 2026 notes such as `isCrypto` are missing (22 of 25). No llms.txt (404) and no Markdown docs (0). 96 of 98 operations carry a long description with defaults, sandbox limits and, for the seven deprecated ones, the replacement (16 of 20). Definitions hold 204 enums, but query parameters such as `container` and `baseType` are plain strings with allowed values only in the description, and `dataset$filter` is a free expression (9 of 15). The file has no examples. The docs site shows sample requests and responses, and each operation lists its 400 errors by `Y` code, with 401 and 404 undescribed (9 of 15). An `Api-Version` header, dated release notes and spec tags by release month (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 58,
          "points": 9.43,
          "reason": "`include` adds optional detail, `top` caps list size at 500, count endpoints exist for transactions and providers, and derived endpoints return net worth and transaction summaries (16 of 25). `skip` and `top` paging with next and previous links in the response header, plus date, account, category, keyword and container filters on transactions (17 of 20). Errors return `errorCode`, `errorMessage` and `referenceCode`, and the spec says codes do not change (15 of 20). No idempotency key or retry guidance. Passing an unused `loginName` to the token call creates a user implicitly, which a retry would not duplicate (4 of 20). Two headers and a token per call. No official server SDK, only client generation from the Swagger file, and FastLink guides for iOS, Android, React Native and Flutter (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 49,
          "points": 8.57,
          "reason": "A `clientId` and `secret` in a form body, never in the URL, are exchanged for a bearer token that expires after 30 minutes and is bound to one user's `loginName` or to the admin. Tokens can be revoked, credentials can be replaced on the dashboard, and each environment has its own. No scopes (22 of 30). A user token reads one user's data, datasets are enabled per customer and the Account Profile dataset needs Yodlee Security Office approval. No read-only credential and no confirmation on deletes (9 of 20). Responses carry bank-written text, and no guidance on untrusted content was found beyond a note on escaped quotes (3 of 15). Consent history endpoints and a `referenceCode` on errors exist. No operator call log was found in public docs, and the dashboard was not read (3 of 15). No security.txt, bug bounty or disclosure address found. The Security FAQ states an annual SOC 2 Type 2 assessment (report under NDA), PCI DSS 4.0.1 Level One and yearly third-party penetration tests (12 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 15,
          "points": 1.88,
          "reason": "No x402, MPP or L402 (0). No price on yodlee.com or the developer portal, both `/pricing` addresses return 404 and product pages ask for a demo (0). The sandbox is free on registration with five preconfigured users. The registration page is disallowed by robots.txt, so we could not confirm that it asks for no card (15 of 20). A person registers in a browser and takes credentials from a dashboard (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 33,
          "points": 2.89,
          "reason": "The newest release notes, July Week 3 2026, are dated 31 July 2026, 69 days before the check (20 of 30). That is the only dated entry since 10 July, so the three-in-90-days line is not met (0). Release notes are dated and appear about every two months. On GitHub, seven issues and pull requests on `Yodlee/OpenAPI` are open, the oldest from April 2021 and the newest from 20 February 2026 with no reply (6 of 15). No official SDKs, and the Swagger file trails the API by four releases (4 of 15). The spec repository has no CI or tests (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 53,
          "points": 4.64,
          "note": "editorial 32, provenance 73",
          "reason": "Closed service with no published service agreement or developer terms. The Swagger file names a Yodlee Developer Licence at an address that returns 404. The spec itself is MIT (8 of 30). The privacy notice says it covers Yodlee's direct-to-consumer services and websites, and that a client's own practices govern services delivered through a client. The Security FAQ says client data is kept until the client deletes it by API or written request, is encrypted with AES-256, and is not used in non-production environments. No DPA is public (12 of 30). No written deprecation policy. The Swagger file marks seven operations deprecated and names replacements, without dates (6 of 20). The FAQ says most core services run from colocation data centres with a move to AWS under way. No sub-processor list or named data locations (6 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`include` adds optional detail, `top` caps list size at 500, count endpoints exist for transactions and providers, and derived endpoints return net worth and transaction summaries (16 of 25). `skip` and `top` paging with next and previous links in the response header, plus date, account, category, keyword and container filters on transactions (17 of 20). Errors return `errorCode`, `errorMessage` and `referenceCode`, and the spec says codes do not change (15 of 20). No idempotency key or retry guidance. Passing an unused `loginName` to the token call creates a user implicitly, which a retry would not duplicate (4 of 20). Two headers and a token per call. No official server SDK, only client generation from the Swagger file, and FastLink guides for iOS, Android, React Native and Flutter (6 of 15).",
          "maintenance": "The newest release notes, July Week 3 2026, are dated 31 July 2026, 69 days before the check (20 of 30). That is the only dated entry since 10 July, so the three-in-90-days line is not met (0). Release notes are dated and appear about every two months. On GitHub, seven issues and pull requests on `Yodlee/OpenAPI` are open, the oldest from April 2021 and the newest from 20 February 2026 with no reply (6 of 15). No official SDKs, and the Swagger file trails the API by four releases (4 of 15). The spec repository has no CI or tests (3 of 10).",
          "payments": "No x402, MPP or L402 (0). No price on yodlee.com or the developer portal, both `/pricing` addresses return 404 and product pages ask for a demo (0). The sandbox is free on registration with five preconfigured users. The registration page is disallowed by robots.txt, so we could not confirm that it asks for no card (15 of 20). A person registers in a browser and takes credentials from a dashboard (0).",
          "reliability": "Graded as a hosted API. No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer (0). With no incident history to read, 5 of 30. No rate limit with numbers was found in the docs or the Swagger file, which lists no 429 response (0). No 429, backoff or idempotency guidance found (0). No public SLA. The Security FAQ mentions only contracted recovery targets for clients' disaster recovery options (0). The Core API v1.1 is generally available (10).",
          "schema": "A public Swagger 2.0 file (`Yodlee/OpenAPI`, MIT) with 70 paths, 98 operations and 267 definitions. Its last update, on 22 April 2026, brought it to the November 2025 release, so fields from the June and July 2026 notes such as `isCrypto` are missing (22 of 25). No llms.txt (404) and no Markdown docs (0). 96 of 98 operations carry a long description with defaults, sandbox limits and, for the seven deprecated ones, the replacement (16 of 20). Definitions hold 204 enums, but query parameters such as `container` and `baseType` are plain strings with allowed values only in the description, and `dataset$filter` is a free expression (9 of 15). The file has no examples. The docs site shows sample requests and responses, and each operation lists its 400 errors by `Y` code, with 401 and 404 undescribed (9 of 15). An `Api-Version` header, dated release notes and spec tags by release month (15).",
          "security": "A `clientId` and `secret` in a form body, never in the URL, are exchanged for a bearer token that expires after 30 minutes and is bound to one user's `loginName` or to the admin. Tokens can be revoked, credentials can be replaced on the dashboard, and each environment has its own. No scopes (22 of 30). A user token reads one user's data, datasets are enabled per customer and the Account Profile dataset needs Yodlee Security Office approval. No read-only credential and no confirmation on deletes (9 of 20). Responses carry bank-written text, and no guidance on untrusted content was found beyond a note on escaped quotes (3 of 15). Consent history endpoints and a `referenceCode` on errors exist. No operator call log was found in public docs, and the dashboard was not read (3 of 15). No security.txt, bug bounty or disclosure address found. The Security FAQ states an annual SOC 2 Type 2 assessment (report under NDA), PCI DSS 4.0.1 Level One and yearly third-party penetration tests (12 of 20).",
          "transparency": "Closed service with no published service agreement or developer terms. The Swagger file names a Yodlee Developer Licence at an address that returns 404. The spec itself is MIT (8 of 30). The privacy notice says it covers Yodlee's direct-to-consumer services and websites, and that a client's own practices govern services delivered through a client. The Security FAQ says client data is kept until the client deletes it by API or written request, is encrypted with AES-256, and is not used in non-production environments. No DPA is public (12 of 30). No written deprecation policy. The Swagger file marks seven operations deprecated and names replacements, without dates (6 of 20). The FAQ says most core services run from colocation data centres with a move to AWS under way. No sub-processor list or named data locations (6 of 20)."
        },
        "sources": [
          {
            "what": "developer portal home",
            "url": "https://developer.yodlee.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Yodlee API overview and datasets",
            "url": "https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "account aggregation getting started and sandbox",
            "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "aggregation API reference",
            "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/api-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "Core APIs reference",
            "url": "https://developer.yodlee.com/products/yodlee/core-apis/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "examples",
            "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/examples",
            "seen": "2026-10-08"
          },
          {
            "what": "account lifecycle",
            "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/account-lifecycle",
            "seen": "2026-10-08"
          },
          {
            "what": "additional resources",
            "url": "https://developer.yodlee.com/products/yodlee/account-aggregation/docs/additional-resources",
            "seen": "2026-10-08"
          },
          {
            "what": "client credentials authorisation",
            "url": "https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "environments",
            "url": "https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/environments",
            "seen": "2026-10-08"
          },
          {
            "what": "FastLink 4 overview",
            "url": "https://developer.yodlee.com/resources/yodlee/fastlink-4/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "FastLink API integrations",
            "url": "https://developer.yodlee.com/resources/yodlee/fastlink-4/docs/api_integrations",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://developer.yodlee.com/resources/yodlee/webhooks/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "data extracts",
            "url": "https://developer.yodlee.com/resources/yodlee/data-extracts/docs/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "US open banking",
            "url": "https://developer.yodlee.com/products/yodlee/us-open-banking/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "generating clients from the Swagger file",
            "url": "https://developer.yodlee.com/resources/yodlee/open-api-swagger/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes index",
            "url": "https://developer.yodlee.com/resources/yodlee",
            "seen": "2026-10-08"
          },
          {
            "what": "July Week 3 2026 release notes",
            "url": "https://developer.yodlee.com/resources/yodlee/july-week-3-2026-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "June 2026 release notes",
            "url": "https://developer.yodlee.com/resources/yodlee/june-2026-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "April 2026 release notes",
            "url": "https://developer.yodlee.com/resources/yodlee/april-2026-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "February 2026 release notes",
            "url": "https://developer.yodlee.com/resources/yodlee/february-2026-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger file repository, history and tags",
            "url": "https://github.com/Yodlee/OpenAPI",
            "seen": "2026-10-08"
          },
          {
            "what": "repository statistics and open issues",
            "url": "https://api.github.com/repos/Yodlee/OpenAPI",
            "seen": "2026-10-08"
          },
          {
            "what": "developer terms address from the Swagger file, 404",
            "url": "https://developer.yodlee.com/terms/condition",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt, 404",
            "url": "https://developer.yodlee.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.yodlee.com/legal/yodlee-security",
            "seen": "2026-10-08"
          },
          {
            "what": "Security FAQ, version 1.0",
            "url": "https://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://www.yodlee.com/legal/privacy-notice",
            "seen": "2026-10-08"
          },
          {
            "what": "company history",
            "url": "https://www.yodlee.com/company",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing address, 404",
            "url": "https://www.yodlee.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt address, returns the home page",
            "url": "https://www.yodlee.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/yodlee.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the API host for each environment. The public docs give paths such as `/ysl/accounts` and say credentials and endpoints are on the dashboard, which needs a login",
          "unchecked: whether registration asks for a card and which agreement a developer accepts. `/user/register` is disallowed by the developer portal's robots.txt and was not fetched",
          "unchecked: the Postman quick start guide linked from the docs, which is hosted by Postman and drawn by script",
          "unchecked: the SOC 2 Type 2 report, which the Security FAQ places under NDA",
          "No price, service agreement, SLA, status page, rate limit, bug bounty or sub-processor list was found in the pages read",
          "status.yodlee.com did not answer from our network and no status page is linked from the site, so the status page is scored as absent",
          "Production and development environments are named in the docs, but how access to them is granted was not established",
          "Some pages were fetched shortly after midnight on 9 October 2026. The batch date of 8 October is used throughout, as the brief requires"
        ]
      },
      "negative": 0,
      "verdict": "A public Swagger 2.0 file covers 98 operations with per-operation error codes, and tokens last 30 minutes and are bound to one end user. No price, service terms, status page, rate limit or SLA is published, there is no official server SDK, and the sandbox is limited to five preconfigured users with sample data.",
      "bestFor": "A bank, wealth firm or fintech with a Yodlee contract that needs wide account coverage, including investment holdings, loans and insurance, in the US, UK, Australia and India.",
      "strengths": [
        "Public Swagger 2.0 file on GitHub (MIT) with 98 operations, 267 definitions and `Y`-prefixed error codes listed per operation",
        "Access tokens expire after 30 minutes, are bound to one end user's `loginName`, and can be revoked with `DELETE /auth/token`",
        "Free sandbox on registration with five preconfigured test users, per the docs",
        "Consent endpoints list, renew and record open banking consents, and `DELETE /user/unregister` removes a user and their data",
        "The Security FAQ states an annual SOC 2 Type 2 assessment, PCI DSS 4.0.1 Level One certification and yearly third-party penetration tests"
      ],
      "weaknesses": [
        "No public price, service agreement or developer terms. The terms address named in the Swagger file returns 404",
        "No status page, rate limit, 429 guidance, idempotency key or SLA was found in the pages read",
        "No official server SDK. Yodlee's docs tell developers to generate a client from the Swagger file",
        "The Swagger file was last updated on 22 April 2026 to the November 2025 release and lacks fields added in June and July 2026, such as `isCrypto`",
        "The sandbox cannot register new users, and full account numbers and holder details need Yodlee Security Office approval",
        "The privacy notice covers only Yodlee's own consumer services and websites, and no DPA or sub-processor list is public"
      ],
      "agentNotes": [
        "Get a token with `POST /auth/token`, sending `Api-Version: 1.1` and the end user's `loginName` as headers and `clientId` and `secret` in a form body. Reuse it for up to 30 minutes",
        "Use the admin `loginName` only for administrative calls such as webhook subscriptions. A token made with a user's `loginName` reads only that user's data",
        "In the sandbox, pick one of the five preconfigured users. Registering new users is not supported there",
        "Page `GET /transactions` with `skip` and `top` (1 to 500). Without dates it returns the last 30 days, and at most two years with `fromDate` and `toDate`",
        "A person must link accounts in FastLink 4 first. Then read `GET /providerAccounts` for link status before `GET /accounts`",
        "Subscribe to `DATA_UPDATES` or `REFRESH` webhooks, or poll `GET /dataExtracts/events` in windows of at most 60 minutes, and do not poll accounts in a loop"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 41.9
        }
      ],
      "editorialScores": {
        "ergonomics": 58,
        "maintenance": 33,
        "payments": 15,
        "reliability": 15,
        "schema": 71,
        "security": 49,
        "transparency": 32
      },
      "provenanceScore": 73
    },
    "connect": {
      "http": "POST /auth/token\nApi-Version: 1.1\nloginName: \u003cloginName\u003e\nContent-Type: application/x-www-form-urlencoded\n\nclientId=\u003cclientId\u003e\u0026secret=\u003csecret\u003e"
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/yodlee-financial-data"
    },
    "notable": [
      "The sandbox is free on registration and holds five preconfigured users. New users cannot be registered there and access is limited to sample data (https://developer.yodlee.com/products/yodlee/account-aggregation/docs)",
      "Access tokens expire after 30 minutes and are tied to one `loginName`. Yodlee replaced JSON Web Tokens with client credentials (https://developer.yodlee.com/resources/yodlee/client-credentials-authorization/docs/overview)",
      "The API is built on datasets. Basic Aggregation Data covers balances, transactions, holdings and statements, and the Account Profile dataset (full account number, holder names, bank transfer code) needs Yodlee Security Office approval (https://developer.yodlee.com/resources/yodlee/yodlee-api-overview/docs)",
      "Yodlee says the core API supports 90 per cent of the top-volume sites in the United States, United Kingdom, Australia and India, and FastLink lists the United States, Canada, Latin America, the United Kingdom, Australia and New Zealand, and South Africa as regions (https://developer.yodlee.com/resources/yodlee/fastlink-4/docs)",
      "The Swagger 2.0 file has 98 operations and was last updated on 22 April 2026 to the November 2025 release (https://github.com/Yodlee/OpenAPI)",
      "The June 2026 release lets `POST /auth/token` accept optional user name, phone and email fields, and the July Week 3 2026 release adds an `isCrypto` flag on investment transactions (https://developer.yodlee.com/resources/yodlee/june-2026-release-notes)",
      "The Security FAQ states an annual SOC 2 Type 2 assessment with the report under NDA, PCI DSS 4.0.1 Level One certification, and retention of client data until the client deletes it or is decommissioned (https://www.yodlee.com/wp-content/uploads/2025-08/Yodlee-Security-FAQ-V1.pdf)",
      "No MCP server was found in Yodlee's docs or in the official MCP registry (https://registry.modelcontextprotocol.io/v0.1/servers?search=yodlee)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Environments",
        "value": "Sandbox (free, five preconfigured users, sample data), development and production, each with its own credentials. The docs print paths such as `/ysl/accounts` without a host"
      },
      {
        "label": "Version",
        "value": "Core API v1.1, set with the `Api-Version: 1.1` header, designed to work with FastLink 4"
      },
      {
        "label": "Products",
        "value": "Account aggregation, account verification (including challenge deposits in the US), transaction data enrichment, holdings, statements and documents, derived net worth and summaries, processor tokens, open banking consents"
      },
      {
        "label": "Countries",
        "value": "Yodlee names the United States, United Kingdom, Australia and India for the core API. FastLink regions add Canada, Latin America, New Zealand and South Africa, with open banking flows for the US, UK, EU and Australia"
      },
      {
        "label": "Rate limits",
        "value": "Not found in the docs or the Swagger file"
      },
      {
        "label": "Test data",
        "value": "Five pre-registered sandbox users and Yodlee's Dummy Account Generator site"
      },
      {
        "label": "Consent and revocation",
        "value": "FastLink 4 handles linking and open banking consent. `GET /consents`, consent renewal and consent history endpoints, `DELETE /providerAccounts/{providerAccountId}`, `DELETE /accounts/{accountId}` and `DELETE /user/unregister`"
      },
      {
        "label": "Pagination",
        "value": "`skip` and `top` (1 to 500) with next and previous links in the response header. Transactions default to the last 30 days and reach back two years"
      },
      {
        "label": "Errors",
        "value": "JSON with `errorCode` (format `YNNN`), `errorMessage` and `referenceCode`. The Swagger file lists 400 errors per operation and no 429"
      },
      {
        "label": "Webhooks",
        "value": "`REFRESH`, `DATA_UPDATES`, `AUTO_REFRESH_UPDATES`, `LATEST_BALANCE_UPDATES`, account verification events and open banking consent events"
      },
      {
        "label": "SDKs",
        "value": "No official server SDK. Clients are generated from the Swagger file. FastLink 4 guides cover web, iOS, Android, React Native and Flutter"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 assessed yearly (report under NDA) and PCI DSS 4.0.1 Level One, per the Security FAQ"
      }
    ],
    "provenance": {
      "legalEntity": "Yodlee, Inc.",
      "domain": "yodlee.com",
      "domainRegistered": "1999-02-09",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://developer.yodlee.com/resources/yodlee",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The privacy notice names Yodlee, Inc. and its subsidiaries Yodlee Credit, LLC, Yodlee Data Services, LLC and Yodlee Infotech Private Limited. The company page says Yodlee was acquired by Envestnet in 2015 and joined the STG portfolio in 2025.",
        "`terms` is left out. No service agreement or developer terms are published. The Swagger file gives https://developer.yodlee.com/terms/condition as its terms of service, and that address returns 404.",
        "`privacy` is left out. The privacy notice at https://www.yodlee.com/legal/privacy-notice says it applies to Yodlee's direct-to-consumer services and websites, and that a client's own privacy practices apply to services delivered through a Yodlee client, which is how API data is handled.",
        "`endpointOnVendorDomain` is null. The public docs print API paths without a host, and the host is given with the credentials on a dashboard we did not read.",
        "No status page is linked from yodlee.com or the developer portal, and status.yodlee.com did not answer.",
        "https://www.yodlee.com/.well-known/security.txt returns the home page, and the same path on developer.yodlee.com returns 404.",
        "Verisign's RDAP server gives a registration date of 1999-02-09 and CSC Corporate Domains, Inc. as registrar."
      ],
      "score": 73,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Yodlee, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "yodlee.com, registered 1999-02-09 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the Proprietary service. The Swagger file on GitHub is MIT licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "nothing hosted, not scored",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/yodlee-financial-data.json"
  }
}
