{
  "fixes": {
    "slug": "kintsugi",
    "name": "Kintsugi",
    "listing": "https://www.anchorterminal.com/tools/kintsugi",
    "markdown": "# Fix list: Kintsugi\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/kintsugi, the October 2026 research run, assessed 8 October 2026. Grade C, 60.7 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Kintsugi: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 13 out of 100, up to 10.9 more on the total\n\nWhy it scored 13: No x402, MPP or L402 (0). Free is $0 and Starter starts at $75 per filing or registration, both public, but API access is listed only under Premium, which is priced on request (5). The Free plan needs no card, and the account-data MCP server asks only for a Kintsugi login. API keys need a paid plan that includes them, so we scored the free tier as partial (8). Signup happens in a browser, and the endpoint that creates API keys accepts only a signed-in Owner or Admin session token (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Security \u0026 auth, 52 out of 100, up to 8.4 more on the total\n\nWhy it scored 52: Two credential models. An API key is tied to one organisation, shown once, revocable at once, with optional expiry and several keys allowed for rotation, and no scopes (22 on its own). The account-data MCP server uses OAuth 2.1 with PKCE (S256), dynamic client registration and one scope, `read:user_data` (27 on its own). Scored between the two (24). Kintsugi says all 46 tools on the account-data server are read-only, the docs MCP server marks 23 of its 55 tools as changing data and tells the client to confirm with the user, and key management needs an Owner or Admin session. The API key has no read-only mode (13). Responses carry customer names and descriptions written by others, and no injection guidance was found (3). Every error carries a `requestId`. No audit log of API calls was found (2). SOC 2 Type II per the security page and a 72-hour breach notice in the terms. No `security.txt`, disclosure policy or bug bounty found (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 3. Reliability, 73 out of 100, up to 5.4 more on the total\n\nWhy it scored 73: Graded on the public API with the hosted lines. Statuspage at status.trykintsugi.com with five components, among them API (20). No incident in the 90 days to 8 October 2026. The only real entry is 16 March 2026, elevated API errors, minor, about seven and a half hours (30). No general rate limit was found in the docs. One endpoint, `POST /filings/{filing_id}/enhanced-data/rebuild`, states 10 requests a minute (2). The error guide says to retry 429, 500 and 503 with exponential backoff and jitter, creates are idempotent on `externalId` and `source`, and one import endpoint takes an `idempotencyKey`. No `Retry-After` header is documented (11). The pricing page lists SLA-backed premium support, and no uptime SLA document was found (0). The Tenanted API and v1 carry no beta label (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 4. Agent ergonomics, 75 out of 100, up to 4.1 more on the total\n\nWhy it scored 75: List endpoints take `limit` and a cursor, with no field selection found. The docs MCP server returns 55 tool definitions of about 185 KB in all, three of them over 25 KB each, and the account-data server has 46 (10). Keyset cursors, sort and order, and filters by date, status, source, customer and country (18). One envelope with a stable `code`, `requestId` and field-level `errors` naming each field. v1 error shapes vary by endpoint, per the changelog (18). Creates are idempotent on `externalId` and `source`, and all 55 MCP tools set readOnlyHint, destructiveHint and idempotentHint. No general idempotency key header (17). Five official SDKs (Python, TypeScript, Java, PHP, Ruby), which cover v1 only. An estimate needs three required fields plus line items and an address (12).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Transparency \u0026 trust, 60 out of 100, up to 3.5 more on the total\n\nMade of editorial 44, provenance 75.\n\nWhy it scored 60: Closed service with clear terms, last updated 29 September 2026, naming Kintsugi AI, Inc. of Delaware. The SDKs are MIT (15). The terms give 60 days to retrieve data after termination and deletion on request, and allow Customer Data to be used to improve the models Kintsugi runs for all customers. The DPA of 26 August 2026 says processing happens in the United States and promises 30 days' notice of a new sub-processor. The privacy policy is dated 13 April 2025 (17). No deprecation policy with dates was found. v1 is labelled legacy with no end date, and deprecated fields are described as removed in future releases (5). The DPA states the United States as the processing location. No sub-processor list was found on the public pages, and the Drata trust centre was not read (7).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Domain age: trykintsugi.com, registered 2023-03-10 (3 years) (7 of 15)\n- Terms of service: read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points (4 of 10)\n- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)\n- security.txt: not found (0 of 10)\n\n## 6. Schema \u0026 documentation, 87 out of 100, up to 2.1 more on the total\n\nWhy it scored 87: OpenAPI 3.1 is public at `https://api.trykintsugi.com/openapi.json` with 901 operations, covering v1, partner and admin paths. No downloadable file was found for the date-versioned Tenanted API, whose 287 operations a release are documented in the reference (22). `llms.txt`, a `.md` twin of every page and `llms-full.txt` (10). Reference pages state what a call does, when a selector is needed and what each status means, and MCP tool descriptions say whether a call is read-only or changes data. Some v1 descriptions are one line (16). 205 enums and 683 maxLength constraints in the spec, with required fields marked. Several v1 filters are free strings that take comma-separated values (12). 866 examples in the spec, plus a documented error envelope and a table of 20 error codes (14). Tenanted releases are dated and chosen with `Api-Version`, and the changelog is public with dated entries. Changes marked breaking were applied to the pinned 2026-07-21 release (13).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 7. Maintenance \u0026 community, 78 out of 100, up to 1.9 more on the total\n\nWhy it scored 78: The API changelog's newest entry is 7 October 2026, and release 2026-10-06 shipped the day before (30). 33 changelog entries on eight dates from 17 September to 7 October 2026 (20). Closed service with a public changelog, support by email, phone and live chat, and a developer community marked coming soon (10). Five official SDKs generated with Speakeasy. Python 0.13.0 is dated 15 September 2026 and `@kintsugi-tax/tax-platform-sdk` 0.10.2 is dated 7 July 2026, and they cover v1 only. Neither MCP server is in the official registry (11). The Python SDK repository is MIT with Dependabot updates merged (7).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## Deductions\n\nEach comes off the total. A fixed and documented problem counts for less at the next check.\n\n- 2 to 7 October 2026. The API changelog marks five changes applied to the pinned 2026-07-21 release as breaking (address access rules and import `userId` on 2 October, filing pause window and a changed error code on 5 October, billing callers on 7 October), while the docs say a pinned release can't change an integration. Each is documented with migration steps on the day, so we deducted the minimum of 3. No advance notice was found (https://docs.trykintsugi.com/reference/changelog)\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the Drata trust centre at app.drata.com linked from the security page, which may hold a sub-processor list and the SOC 2 report. We didn't load it\n- unchecked: the live tool definitions of the account-data MCP server, which need a Kintsugi login. The count of 46 and the read-only claim come from the help centre and the announcement\n- unchecked: Maven Central, Packagist and RubyGems for the Java, PHP and Ruby SDKs. We read npm, PyPI and the Python repository only\n- Whether advance notice of the breaking changes of September and October 2026 reached customers by email. None was found in the changelog or docs\n- Whether the docs MCP server calls the API. The setup guide says it never proxies calls or sees credentials, while its own configuration sends `X-API-KEY` and the server's instructions say each tool calls the API with that key\n- Whether the account-data MCP server works on the Free plan. The help article asks for an active account and names no plan\n- What the general rate limits are. Only one endpoint states a number\n- Whether an uptime SLA exists in Premium contracts. The pricing page names SLA-backed premium support only\n- No downloadable OpenAPI file was found for the Tenanted API. The public file covers v1, partner and admin paths\n- The terms bar using the services to train or improve any machine-learning model and bar competitors from benchmarking. Recorded as a fact with no deduction\n\n## Weaknesses\n\n- API access, SDKs and real-time tax calculation are listed only under Premium, which is priced on request. API keys need a paid plan that includes them\n- Nine changelog entries from 17 September to 7 October 2026 are marked breaking, five on the pinned 2026-07-21 release and four on v1. No advance notice was found\n- No general rate limit is published and no `Retry-After` header is documented. The docs say only to retry 429, 500 and 503 with backoff\n- API keys act on a whole organisation with no scopes or read-only mode. Expiry is the only setting\n- No `security.txt`, disclosure policy, bug bounty, uptime SLA document or subprocessor list was found on the public pages\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Send `Api-Key` and pin `Api-Version` (for example `2026-10-06`) on Tenanted API calls to `https://api.trykintsugi.com`. Without the header a request runs against `2026-07-21`\n- Use `x-api-key` and `x-organization-id` with `/v1` paths for the SDKs and the docs MCP server. They don't cover the Tenanted API\n- Call `POST /tax-estimations` for a quote. Nothing is stored. Record the sale with a transaction create, which answers 202, then check `processingStatus` before reading tax totals\n- Always send `externalId` on creates. A repeat with the same `externalId` and `source` returns the stored record with 200 and doesn't apply the new fields\n- Branch on the error `code`, not the message. Retry 429, 500 and 503 with exponential backoff, and restart paging from the first page on `stale_cursor`\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "C",
    "score": 60.7,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 13,
        "maxGain": 10.9,
        "reason": "No x402, MPP or L402 (0). Free is $0 and Starter starts at $75 per filing or registration, both public, but API access is listed only under Premium, which is priced on request (5). The Free plan needs no card, and the account-data MCP server asks only for a Kintsugi login. API keys need a paid plan that includes them, so we scored the free tier as partial (8). Signup happens in a browser, and the endpoint that creates API keys accepts only a signed-in Owner or Admin session token (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 52,
        "maxGain": 8.4,
        "reason": "Two credential models. An API key is tied to one organisation, shown once, revocable at once, with optional expiry and several keys allowed for rotation, and no scopes (22 on its own). The account-data MCP server uses OAuth 2.1 with PKCE (S256), dynamic client registration and one scope, `read:user_data` (27 on its own). Scored between the two (24). Kintsugi says all 46 tools on the account-data server are read-only, the docs MCP server marks 23 of its 55 tools as changing data and tells the client to confirm with the user, and key management needs an Owner or Admin session. The API key has no read-only mode (13). Responses carry customer names and descriptions written by others, and no injection guidance was found (3). Every error carries a `requestId`. No audit log of API calls was found (2). SOC 2 Type II per the security page and a 72-hour breach notice in the terms. No `security.txt`, disclosure policy or bug bounty found (10).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 73,
        "maxGain": 5.4,
        "reason": "Graded on the public API with the hosted lines. Statuspage at status.trykintsugi.com with five components, among them API (20). No incident in the 90 days to 8 October 2026. The only real entry is 16 March 2026, elevated API errors, minor, about seven and a half hours (30). No general rate limit was found in the docs. One endpoint, `POST /filings/{filing_id}/enhanced-data/rebuild`, states 10 requests a minute (2). The error guide says to retry 429, 500 and 503 with exponential backoff and jitter, creates are idempotent on `externalId` and `source`, and one import endpoint takes an `idempotencyKey`. No `Retry-After` header is documented (11). The pricing page lists SLA-backed premium support, and no uptime SLA document was found (0). The Tenanted API and v1 carry no beta label (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 75,
        "maxGain": 4.1,
        "reason": "List endpoints take `limit` and a cursor, with no field selection found. The docs MCP server returns 55 tool definitions of about 185 KB in all, three of them over 25 KB each, and the account-data server has 46 (10). Keyset cursors, sort and order, and filters by date, status, source, customer and country (18). One envelope with a stable `code`, `requestId` and field-level `errors` naming each field. v1 error shapes vary by endpoint, per the changelog (18). Creates are idempotent on `externalId` and `source`, and all 55 MCP tools set readOnlyHint, destructiveHint and idempotentHint. No general idempotency key header (17). Five official SDKs (Python, TypeScript, Java, PHP, Ruby), which cover v1 only. An estimate needs three required fields plus line items and an address (12).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 60,
        "maxGain": 3.5,
        "reason": "Closed service with clear terms, last updated 29 September 2026, naming Kintsugi AI, Inc. of Delaware. The SDKs are MIT (15). The terms give 60 days to retrieve data after termination and deletion on request, and allow Customer Data to be used to improve the models Kintsugi runs for all customers. The DPA of 26 August 2026 says processing happens in the United States and promises 30 days' notice of a new sub-processor. The privacy policy is dated 13 April 2025 (17). No deprecation policy with dates was found. v1 is labelled legacy with no end date, and deprecated fields are described as removed in future releases (5). The DPA states the United States as the processing location. No sub-processor list was found on the public pages, and the Drata trust centre was not read (7).",
        "blend": "editorial 44, provenance 75",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 87,
        "maxGain": 2.1,
        "reason": "OpenAPI 3.1 is public at `https://api.trykintsugi.com/openapi.json` with 901 operations, covering v1, partner and admin paths. No downloadable file was found for the date-versioned Tenanted API, whose 287 operations a release are documented in the reference (22). `llms.txt`, a `.md` twin of every page and `llms-full.txt` (10). Reference pages state what a call does, when a selector is needed and what each status means, and MCP tool descriptions say whether a call is read-only or changes data. Some v1 descriptions are one line (16). 205 enums and 683 maxLength constraints in the spec, with required fields marked. Several v1 filters are free strings that take comma-separated values (12). 866 examples in the spec, plus a documented error envelope and a table of 20 error codes (14). Tenanted releases are dated and chosen with `Api-Version`, and the changelog is public with dated entries. Changes marked breaking were applied to the pinned 2026-07-21 release (13).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 78,
        "maxGain": 1.9,
        "reason": "The API changelog's newest entry is 7 October 2026, and release 2026-10-06 shipped the day before (30). 33 changelog entries on eight dates from 17 September to 7 October 2026 (20). Closed service with a public changelog, support by email, phone and live chat, and a developer community marked coming soon (10). Five official SDKs generated with Speakeasy. Python 0.13.0 is dated 15 September 2026 and `@kintsugi-tax/tax-platform-sdk` 0.10.2 is dated 7 July 2026, and they cover v1 only. Neither MCP server is in the official registry (11). The Python SDK repository is MIT with Dependabot updates merged (7).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Domain age",
        "value": "trykintsugi.com, registered 2023-03-10 (3 years)",
        "points": 7,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points",
        "points": 4,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 7 of the 8 things a reader expects",
        "points": 9.3,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "deductions": [
      "2 to 7 October 2026. The API changelog marks five changes applied to the pinned 2026-07-21 release as breaking (address access rules and import `userId` on 2 October, filing pause window and a changed error code on 5 October, billing callers on 7 October), while the docs say a pinned release can't change an integration. Each is documented with migration steps on the day, so we deducted the minimum of 3. No advance notice was found (https://docs.trykintsugi.com/reference/changelog)"
    ],
    "unchecked": [
      "unchecked: the Drata trust centre at app.drata.com linked from the security page, which may hold a sub-processor list and the SOC 2 report. We didn't load it",
      "unchecked: the live tool definitions of the account-data MCP server, which need a Kintsugi login. The count of 46 and the read-only claim come from the help centre and the announcement",
      "unchecked: Maven Central, Packagist and RubyGems for the Java, PHP and Ruby SDKs. We read npm, PyPI and the Python repository only",
      "Whether advance notice of the breaking changes of September and October 2026 reached customers by email. None was found in the changelog or docs",
      "Whether the docs MCP server calls the API. The setup guide says it never proxies calls or sees credentials, while its own configuration sends `X-API-KEY` and the server's instructions say each tool calls the API with that key",
      "Whether the account-data MCP server works on the Free plan. The help article asks for an active account and names no plan",
      "What the general rate limits are. Only one endpoint states a number",
      "Whether an uptime SLA exists in Premium contracts. The pricing page names SLA-backed premium support only",
      "No downloadable OpenAPI file was found for the Tenanted API. The public file covers v1, partner and admin paths",
      "The terms bar using the services to train or improve any machine-learning model and bar competitors from benchmarking. Recorded as a fact with no deduction"
    ],
    "weaknesses": [
      "API access, SDKs and real-time tax calculation are listed only under Premium, which is priced on request. API keys need a paid plan that includes them",
      "Nine changelog entries from 17 September to 7 October 2026 are marked breaking, five on the pinned 2026-07-21 release and four on v1. No advance notice was found",
      "No general rate limit is published and no `Retry-After` header is documented. The docs say only to retry 429, 500 and 503 with backoff",
      "API keys act on a whole organisation with no scopes or read-only mode. Expiry is the only setting",
      "No `security.txt`, disclosure policy, bug bounty, uptime SLA document or subprocessor list was found on the public pages"
    ],
    "agentNotes": [
      "Send `Api-Key` and pin `Api-Version` (for example `2026-10-06`) on Tenanted API calls to `https://api.trykintsugi.com`. Without the header a request runs against `2026-07-21`",
      "Use `x-api-key` and `x-organization-id` with `/v1` paths for the SDKs and the docs MCP server. They don't cover the Tenanted API",
      "Call `POST /tax-estimations` for a quote. Nothing is stored. Record the sale with a transaction create, which answers 202, then check `processingStatus` before reading tax totals",
      "Always send `externalId` on creates. A repeat with the same `externalId` and `source` returns the stored record with 200 and doesn't apply the new fields",
      "Branch on the error `code`, not the message. Retry 429, 500 and 503 with exponential backoff, and restart paging from the first page on `stale_cursor`"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
